PT-2025-31677 · Unknown · Pearcleaner

Swayzgl1Tzyyy

·

Published

2025-08-01

·

Updated

2025-08-03

·

CVE-2025-54595

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pearcleaner versions 4.4.0 through 4.5.1
Description Pearcleaner is a macOS application cleaner. The PearcleanerHelper, a privileged helper tool bundled with the application, registers an XPC service (com.alienator88.Pearcleaner.PearcleanerHelper) that accepts unauthenticated connections from any local process. This service exposes a method that executes arbitrary shell commands, allowing local unprivileged users to escalate privileges to root after the helper is approved and active.
Recommendations Update to version 4.5.2 or later.

Exploit

Fix

LPE

Improper Privilege Management

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-54595
GHSA-GR2J-65FH-8PVC

Affected Products

Pearcleaner