PT-2025-32540 · Gimp · Gimp
Karol Mazurek
·
Published
2025-08-11
·
Updated
2025-09-12
·
CVE-2025-8672
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
GIMP versions prior to 3.1.4.2
Description:
The MacOS version of GIMP includes a Python interpreter that inherits Transparency, Consent, and Control (TCC) permissions granted to the main application. An attacker with local access can use this interpreter to execute arbitrary commands or scripts, potentially accessing user files in privacy-protected folders without prompting the user for approval. Accessing resources beyond previously granted TCC permissions may prompt the user for approval under the guise of GIMP, potentially concealing malicious intent.
Recommendations:
Update to GIMP version 3.1.4.2 or later.
Fix
LPE
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gimp