PT-2025-27829 · Unknown · Remote For Mac
Chokri Hammedi
·
Published
2025-06-08
·
Updated
2025-11-12
·
CVE-2025-34089
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Remote for Mac versions prior to 2025.7
Description
An unauthenticated remote code execution issue exists in Remote for Mac, a macOS remote control utility developed by Aexol Studio. When the application is configured with authentication disabled, the
/api/executeScript API endpoint is exposed without access control. This allows unauthenticated remote attackers to inject arbitrary AppleScript payloads via the X-Script HTTP header, resulting in code execution using do shell script. Successful exploitation grants attackers the ability to run arbitrary commands on the macOS host with the privileges of the Remote for Mac background process.Recommendations
Update Remote for Mac to a version later than 2025.7.
Exploit
Fix
RCE
Missing Authentication
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Remote For Mac