An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with root privileges and Full Disk Access, thus bypassing macOS privacy controls.
References
| Link | Resource |
|---|---|
| http://shirt.com | Broken Link |
| https://shirt-pocket.com/SuperDuper/SuperDuperDescription.html | Product |
| https://www.shirtpocket.com/blog/index.php/shadedgrey/comments/superduper_v312_now_available | Vendor Advisory |
Configurations
History
13 Feb 2026, 20:32
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Shirt-pocket superduper\!
Shirt-pocket |
|
| References | () http://shirt.com - Broken Link | |
| References | () https://shirt-pocket.com/SuperDuper/SuperDuperDescription.html - Product | |
| References | () https://www.shirtpocket.com/blog/index.php/shadedgrey/comments/superduper_v312_now_available - Vendor Advisory | |
| CPE | cpe:2.3:a:shirt-pocket:superduper\!:*:*:*:*:*:*:*:* |
03 Feb 2026, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-276 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
29 Jan 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-29 20:16
Updated : 2026-02-13 20:32
NVD link : CVE-2025-69604
Mitre link : CVE-2025-69604
CVE.ORG link : CVE-2025-69604
JSON object : View
Products Affected
shirt-pocket
- superduper\!
CWE
CWE-276
Incorrect Default Permissions
