CVE-2025-10751

MacForge contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.This issue affects MacForge: 1.2.0 Beta 1.
References
Link Resource
https://fluidattacks.com/advisories/m83 Exploit Third Party Advisory
https://github.com/MacEnhance/MacForge Third Party Advisory
https://www.macenhance.com/macforge Product
https://fluidattacks.com/advisories/m83 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:macenhance:macforge:1.20:beta1:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

History

22 Dec 2025, 19:59

Type Values Removed Values Added
References () https://fluidattacks.com/advisories/m83 - () https://fluidattacks.com/advisories/m83 - Exploit, Third Party Advisory
References () https://github.com/MacEnhance/MacForge - () https://github.com/MacEnhance/MacForge - Third Party Advisory
References () https://www.macenhance.com/macforge - () https://www.macenhance.com/macforge - Product
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
First Time Apple macos
Macenhance
Macenhance macforge
Apple
CPE cpe:2.3:a:macenhance:macforge:1.20:beta1:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

06 Oct 2025, 15:16

Type Values Removed Values Added
References () https://fluidattacks.com/advisories/m83 - () https://fluidattacks.com/advisories/m83 -

04 Oct 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-04 01:15

Updated : 2025-12-22 19:59


NVD link : CVE-2025-10751

Mitre link : CVE-2025-10751

CVE.ORG link : CVE-2025-10751


JSON object : View

Products Affected

macenhance

  • macforge

apple

  • macos
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource