PT-2026-28501 · Unknown · Clearancekit
CVE-2026-33632
·
Publicado
2026-03-26
·
Atualizado
2026-03-26
CVSS v4.0
8.4
Alta
| Vetor | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ClearanceKit versions prior to 4.2.4
Description
ClearanceKit monitors file system access events on macOS and enforces access policies on a per-process basis. Before version 4.2.4, two file operation event types—
ES EVENT TYPE AUTH EXCHANGEDATA and ES EVENT TYPE AUTH CLONE—were not intercepted by ClearanceKit’s opfilter system extension. This allowed local processes to bypass file access policies. The issue was addressed in commit 6181c4a by subscribing to both event types and routing them through the existing policy evaluator.Recommendations
Upgrade to version 4.2.4 or later and reactivate the system extension.
Exploit
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Clearancekit