An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight script with root privileges and Full Disk Access, thus bypassing macOS privacy controls.
References
Configurations
History
05 Jul 2026, 02:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
08 Dec 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-284 |
05 Dec 2025, 20:14
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-276 | |
| First Time |
Shirt-pocket superduper\!
Shirt-pocket |
|
| CPE | cpe:2.3:a:shirt-pocket:superduper\!:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
| References | () http://shirt.com - Not Applicable | |
| References | () https://shirt-pocket.com/SuperDuper/SuperDuperDescription.html - Product | |
| References | () https://www.shirtpocket.com/blog/index.php/shadedgrey/comments/superduper_security_update_v311/ - Release Notes |
01 Dec 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-01 16:15
Updated : 2026-07-05 02:17
NVD link : CVE-2025-61229
Mitre link : CVE-2025-61229
CVE.ORG link : CVE-2025-61229
JSON object : View
Products Affected
shirt-pocket
- superduper\!
