CVE-2025-69604

An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with root privileges and Full Disk Access, thus bypassing macOS privacy controls.
Configurations

Configuration 1 (hide)

cpe:2.3:a:shirt-pocket:superduper\!:*:*:*:*:*:*:*:*

History

13 Feb 2026, 20:32

Type Values Removed Values Added
First Time Shirt-pocket superduper\!
Shirt-pocket
References () http://shirt.com - () http://shirt.com - Broken Link
References () https://shirt-pocket.com/SuperDuper/SuperDuperDescription.html - () https://shirt-pocket.com/SuperDuper/SuperDuperDescription.html - Product
References () https://www.shirtpocket.com/blog/index.php/shadedgrey/comments/superduper_v312_now_available - () https://www.shirtpocket.com/blog/index.php/shadedgrey/comments/superduper_v312_now_available - Vendor Advisory
CPE cpe:2.3:a:shirt-pocket:superduper\!:*:*:*:*:*:*:*:*

03 Feb 2026, 17:15

Type Values Removed Values Added
CWE CWE-276
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

29 Jan 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-29 20:16

Updated : 2026-02-13 20:32


NVD link : CVE-2025-69604

Mitre link : CVE-2025-69604

CVE.ORG link : CVE-2025-69604


JSON object : View

Products Affected

shirt-pocket

  • superduper\!
CWE
CWE-276

Incorrect Default Permissions