PT-2025-22984 · Viscosity · Viscosity
Karol Mazurek
·
Published
2025-05-27
·
Updated
2025-05-27
·
CVE-2025-4412
CVSS v4.0
4.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Viscosity versions prior to 1.11.5
Description
The issue allows loading a dynamic library with Viscosity's TCC identity on macOS systems by utilizing a Launch Agent and loading the viscosity openvpn process from the application bundle. The acquired resource access is limited without entitlements such as access to the camera or microphone. Only user-granted permissions for file resources apply. Access to other resources beyond granted-permissions requires user interaction with a system prompt asking for permission.
Recommendations
For versions prior to 1.11.5, update to version 1.11.5 to resolve the issue. As a temporary workaround, consider restricting the use of the viscosity openvpn process until the update is applied.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Viscosity