What we need is true application isolation even in the command line. Treat Terminal as privileged access, not something any app can just command. Sandbox non-app store apps as well.
Whenever I ask Claude to vibecode macOS native apps for me, I always request the apps to be sandboxed. Agents know how to sandbox the apps; just ask. And you can verify it without reading any code.
This is a fluff piece that has zero technical details. But I find your logic very interesting: if the presence of one CVE in sandboxing makes sandboxing untrustworthy, should we not have long ago discounted the entire security of Linux due to many CVEs for privilege escalation? Or the security of any and all browsers?
etatester · · focus · HN ↗
kccqzy · · focus · HN ↗
chrisjj · · focus · HN ↗
... said that OpenAI security guy, no doubt.
kccqzy · · focus · HN ↗
chrisjj · · focus · HN ↗
<a href="https://www.sentinelone.com/vulnerability-database/cve-2026-28826/" rel="nofollow">https://www.sentinelone.com/vulnerability-database/cve-2026-...
kccqzy · · focus · HN ↗
chrisjj · · focus · HN ↗
But we probably should not think "There are several ways using only the GUI to tell whether an app is sandboxed.".
Let's not be that OpenAI guy.