PT-2025-31677 · Unknown · Pearcleaner

Swayzgl1Tzyyy

·

Published

2025-08-01

·

Updated

2025-08-03

·

CVE-2025-54595

CVSS v3.1
7.3
VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions:

Pearcleaner versions 4.4.0 through 4.5.1

Description:

Pearcleaner is a macOS application cleaner. The PearcleanerHelper, a privileged helper tool bundled with the application, registers an XPC service (`com.alienator88.Pearcleaner.PearcleanerHelper`) that accepts unauthenticated connections from any local process. This service exposes a method that executes arbitrary shell commands, allowing local unprivileged users to escalate privileges to root after the helper is approved and active.

Recommendations:

Update to version 4.5.2 or later.

Fix

LPE

Improper Privilege Management

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-54595
GHSA-GR2J-65FH-8PVC

Affected Products

Pearcleaner