PT-2025-27829 · Unknown · Remote For Mac

Chokri Hammedi

·

Published

2025-06-08

·

Updated

2025-11-12

·

CVE-2025-34089

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Remote for Mac versions prior to 2025.7
Description An unauthenticated remote code execution issue exists in Remote for Mac, a macOS remote control utility developed by Aexol Studio. When the application is configured with authentication disabled, the /api/executeScript API endpoint is exposed without access control. This allows unauthenticated remote attackers to inject arbitrary AppleScript payloads via the X-Script HTTP header, resulting in code execution using do shell script. Successful exploitation grants attackers the ability to run arbitrary commands on the macOS host with the privileges of the Remote for Mac background process.
Recommendations Update Remote for Mac to a version later than 2025.7.

Exploit

Fix

RCE

Missing Authentication

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2026-00162
CVE-2025-34089

Affected Products

Remote For Mac