ZeroHour

CVE-2025-69604

CVSS 3.1
7.8 high
EPSS
<1%p1
Published
()
Modified
Description

An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with root privileges and Full Disk Access, thus bypassing macOS privacy controls.

Vendors
shirt-pocket
Products
superduper\!
Weakness
CWE-276
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.