CVE-2025-69604

An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with root privileges and Full Disk Access, thus bypassing macOS privacy controls.
Configurations

No configuration.

History

03 Feb 2026, 17:15

Type Values Removed Values Added
CWE CWE-276
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

Information

Published : 2026-01-29 20:16

Updated : 2026-02-03 17:15


NVD link : CVE-2025-69604

Mitre link : CVE-2025-69604

CVE.ORG link : CVE-2025-69604


JSON object : View

Products Affected

No product.

CWE
CWE-276

Incorrect Default Permissions