← Back

CVE-2025-69604

nvd nist
Published: Jan 29, 2026Modified: Jul 5, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with root privileges and Full Disk Access, thus bypassing macOS privacy controls.

Affected (1)

1 product
Superduper!
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.12

Timeline

No history available yet.