logo

TCC Bypass vulnerabilities in six applications for MacOS

ID: 9c6d2227-64ab-512a-b0a1-efb7caae4848

STIX ID: report--9c6d2227-64ab-512a-b0a1-efb7caae4848

Feed Name: CERT Polska

Threat Score
50/100

Date Published: 2025-08-11

Date Updated: 2026-04-19

Author: CERT Polska

...
...

CERT Polska coordinated disclosure reporting multiple macOS application vulnerabilities (CVE-2025-8672, CVE-2025-53811, CVE-2025-9190, CVE-2025-53813, CVE-2025-8597, CVE-2025-8700) affecting GIMP, Mosh‑Pro, Cursor, Nozbe, MacVim and Invoice Ninja where bundled interpreters, configuration options or the com.apple.security.get-task-allow entitlement can allow a local unprivileged attacker to inherit TCC permissions or attach debuggers and inject code to access privacy-protected data; some issues have been patched while others remain unpatched or rejected by maintainers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.