Skipping the lock: A Claude Code CLI weakness lets any macOS process read stored credentials
ID: c2c6bff7-6a87-552a-bd26-f79e5056febd
STIX ID: report--c2c6bff7-6a87-552a-bd26-f79e5056febd
Feed Name: Security Boulevard
Silverfort reports a macOS implementation weakness in Anthropic's Claude Code CLI: the CLI creates a Keychain item via /usr/bin/security without tightening the ACL, which results in the item being readable by any same-user process without a re-authentication prompt. A malicious process can silently extract long-lived refresh tokens and replay them from another machine to act as the user, enabling access to MCP servers and connected services; recommended defenses include binding the Keychain item to the Claude binary signature, monitoring for security find-generic-password calls, alerting on cross-host token reuse, and rotating credentials on suspicion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
