Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
ClearanceKit: opfilter system extension can be suspended or signalled by a root process, disabling file-access policy enforcement
Vulnerability Description
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.6, the opfilter Endpoint Security system extension (bundle ID uk.craigbass.clearancekit.opfilter) can be suspended with SIGSTOP or kill -STOP, or killed with SIGKILL/SIGTERM, by any process running as root. While the extension is suspended, all AUTH Endpoint Security events time out and default to allow, silently disabling ClearanceKit's file-access policy enforcement for the duration of the suspension. This vulnerability is fixed in 5.0.6.
CVSS Information
N/A
Vulnerability Type
保护机制失效
Vulnerability Title
ClearanceKit 安全漏洞
Vulnerability Description
ClearanceKit是Craig J. Bass个人开发者的一个macOS文件系统访问控制工具。 ClearanceKit 5.0.6之前版本存在安全漏洞,该漏洞源于opfilter Endpoint Security系统扩展可被root进程暂停或终止,可能导致文件访问策略在暂停期间被静默禁用。
CVSS Information
N/A
Vulnerability Type
N/A