PT-2025-48487 · Shirt Pocket · Superduper!

Published

2025-12-01

·

Updated

2025-12-01

·

CVE-2025-61229

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SuperDuper! versions 3.10 and earlier
Description An issue in SuperDuper! versions 3.10 and earlier allows a local attacker to modify the default task template. This modification enables the execution of an arbitrary preflight script with root privileges and Full Disk Access, bypassing macOS privacy controls.
Recommendations Update to a version later than 3.10.

Fix

LPE

Improper Access Control

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2025-61229

Affected Products

Superduper!