CVE-2026-47133

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 5.0.10, each table in the on-disk SQLite policy store (`/Library/Application Support/clearancekit/store.db`) is verified using an ECDSA signature stored in the `data_signatures` table. The signed payload contains only the canonical row content, with no version counter or freshness binding. An attacker who can write `store.db` and the matching `data_signatures` row — feasible during the opfilter-update window when the Endpoint Security filter is offline, or via offline-boot / decrypted-backup scenarios — can substitute a previously-captured legitimately-signed snapshot. opfilter accepts the older snapshot as fully valid on next boot because the existing signatures still verify. Version 5.0.10 patches the issue.
CVSS

No CVSS.

Configurations

No configuration.

History

20 Jul 2026, 22:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-20 22:17

Updated : 2026-07-21 15:16


NVD link : CVE-2026-47133

Mitre link : CVE-2026-47133

CVE.ORG link : CVE-2026-47133


JSON object : View

Products Affected

No product.

CWE
CWE-294

Authentication Bypass by Capture-replay