PT-2024-38682 · Unknown · Sensei Mac Cleaner

Carlos Garrido

·

Published

2024-11-25

·

Updated

2024-11-25

·

CVE-2024-7915

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sensei Mac Cleaner (affected versions not specified)
Description The issue allows an attacker to perform multiple operations as the root user, including arbitrary file deletion and writing, loading and unloading daemons, manipulating file permissions, and loading extensions. The vulnerable module org.cindori.SenseiHelper can be contacted via XPC and is susceptible to a PID Reuse Attack, enabling an attacker to impersonate a legitimate client and send crafted XPC messages to invoke arbitrary methods exposed by the HelperProtocol interface.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-7915

Affected Products

Sensei Mac Cleaner