logo

Skipping the lock: A Claude Code CLI weakness lets any macOS process read stored credentials 

ID: c2c6bff7-6a87-552a-bd26-f79e5056febd

STIX ID: report--c2c6bff7-6a87-552a-bd26-f79e5056febd

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2026-07-28

Date Updated: 2026-07-29

Author: Liad Biton

...
...

Silverfort reports a macOS implementation weakness in Anthropic's Claude Code CLI: the CLI creates a Keychain item via /usr/bin/security without tightening the ACL, which results in the item being readable by any same-user process without a re-authentication prompt. A malicious process can silently extract long-lived refresh tokens and replay them from another machine to act as the user, enabling access to MCP servers and connected services; recommended defenses include binding the Keychain item to the Claude binary signature, monitoring for security find-generic-password calls, alerting on cross-host token reuse, and rotating credentials on suspicion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.