IPVanish VPN for macOS Vulnerability Let Attackers Escalate Privilege and Execute Arbitrary Code
ID: 39f20cde-2f18-58a2-86aa-29ff2276fdd6
STIX ID: report--39f20cde-2f18-58a2-86aa-29ff2276fdd6
Feed Name: cybersecurityNews.com
A critical local privilege escalation (CVE-PENDING, CVSS 8.8) in IPVanish VPN for macOS allows unprivileged local processes to connect to an unauthenticated privileged helper (com.ipvanish.osx.vpnhelper) via XPC and execute arbitrary code as root; SecureLayer7 details how unvalidated OpenVPNPath parameters and a signature-verification logic flaw enable copying and weaponizing attacker-controlled files, provides IOCs (e.g., /tmp/ipvanish_exploit.sh and the helper’s install directory), and recommends immediate fixes (caller authentication, enforce code-signature verification, and path whitelisting).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
