An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with root privileges and Full Disk Access, thus bypassing macOS privacy controls.
References
Configurations
No configuration.
History
03 Feb 2026, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-276 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
Information
Published : 2026-01-29 20:16
Updated : 2026-02-03 17:15
NVD link : CVE-2025-69604
Mitre link : CVE-2025-69604
CVE.ORG link : CVE-2025-69604
JSON object : View
Products Affected
No product.
CWE
CWE-276
Incorrect Default Permissions
