CVE-2025-10751

MacForge contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.This issue affects MacForge: 1.2.0 Beta 1.
References
Link Resource
https://fluidattacks.com/advisories/m83 Exploit Third Party Advisory
https://github.com/MacEnhance/MacForge Third Party Advisory
https://www.macenhance.com/macforge Product
https://fluidattacks.com/advisories/m83 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:macenhance:macforge:1.20:beta1:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-10-04 01:15

Updated : 2025-12-22 19:59


NVD link : CVE-2025-10751

Mitre link : CVE-2025-10751

CVE.ORG link : CVE-2025-10751


JSON object : View

Products Affected

apple

  • macos

macenhance

  • macforge
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource