PT-2025-51855 · Mattermost · Mattermost Desktop App

Karmaz95

·

Published

2025-12-17

·

Updated

2025-12-17

·

CVE-2025-13326

CVSS v3.1

3.9

Low

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions prior to 6.0.0
Description The Mattermost Desktop App does not enable the Hardened Runtime when packaged for the Mac App Store for versions prior to 6.0.0. This allows an attacker to obtain TCC permissions by copying the application binary to a temporary folder. TCC (Transparency, Consent, and Control) is a macOS security feature that manages user permissions for accessing protected resources. Inheriting these permissions could allow unauthorized access to sensitive data.
Recommendations Update to Mattermost Desktop App version 6.0.0 or later.

Fix

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-13326

Affected Products

Mattermost Desktop App