PT-2025-39246 · Magnetism Studios · Endurance

·

CVE-2025-10906

·

Published

2025-09-24

·

Updated

2025-09-29

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Magnetism Studios Endurance versions up to 3.3.0
Description A security issue exists in Magnetism Studios Endurance on macOS. The loadModuleNamed:WithReply function within the file /Applications/Endurance.app/Contents/Library/LaunchServices/com.MagnetismStudios.endurance.helper component, specifically the NSXPC Interface, is susceptible to manipulation that can result in missing authentication. The attack requires local access.
Recommendations Versions prior to 3.3.0 should be updated.

Exploit

Fix

Missing Authentication

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-10906

Affected Products

Endurance