PT-2025-35539 · Alaneuler · Batterykid

Swayzgl1Tzyyy

·

Published

2025-09-02

·

Updated

2025-09-07

·

CVE-2025-9815

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions alaneuler batteryKid versions 2.0 through 2.1
Description A weakness has been identified in alaneuler batteryKid on macOS. The affected element is an unknown function within the file PrivilegeHelper/PrivilegeHelper.swift of the NSXPCListener component. This manipulation results in missing authentication, allowing for local attacks. The exploit has been made publicly available.
Recommendations Restrict access to the NSXPCListener component. Disable the affected function PrivilegeHelper/PrivilegeHelper.swift.

Exploit

Fix

LPE

Missing Authentication

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-9815

Affected Products

Batterykid