Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
ClearanceKit: Ad-hoc signed binaries can spoof Apple process identities in the global allowlist
Vulnerability Description
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.5, ClearanceKit incorrectly treats a process with an empty Team ID and a non-empty Signing ID as an Apple platform binary. This bug allows a malicious software to impersonate an apple process in the global allowlist, and access all protected files. This vulnerability is fixed in 5.0.5.
CVSS Information
N/A
Vulnerability Type
授权机制不正确
Vulnerability Title
ClearanceKit 安全漏洞
Vulnerability Description
ClearanceKit是Craig J. Bass个人开发者的一个macOS文件系统访问控制工具。 ClearanceKit 5.0.5之前版本存在安全漏洞,该漏洞源于错误处理Team ID和Signing ID,可能导致恶意软件冒充Apple进程并访问所有受保护文件。
CVSS Information
N/A
Vulnerability Type
N/A