PT-2026-28501 · Unknown · Clearancekit

CVE-2026-33632

·

Publicado

2026-03-26

·

Atualizado

2026-03-26

CVSS v4.0

8.4

Alta

VetorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ClearanceKit versions prior to 4.2.4
Description ClearanceKit monitors file system access events on macOS and enforces access policies on a per-process basis. Before version 4.2.4, two file operation event types—ES EVENT TYPE AUTH EXCHANGEDATA and ES EVENT TYPE AUTH CLONE—were not intercepted by ClearanceKit’s opfilter system extension. This allowed local processes to bypass file access policies. The issue was addressed in commit 6181c4a by subscribing to both event types and routing them through the existing policy evaluator.
Recommendations Upgrade to version 4.2.4 or later and reactivate the system extension.

Exploit

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33632
GHSA-WPXJ-VHFP-HHVM

Produtos afetados

Clearancekit