PT-2025-52244 · Arduino · Arduino Ide

Karmaz95

+1

·

Published

2025-12-18

·

Updated

2026-02-19

·

CVE-2025-64723

CVSS v4.0

4.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Arduino IDE versions prior to 2.3.7
Description Arduino IDE for macOS, before version 2.3.7, had overly permissive security entitlements. This configuration bypassed macOS Hardened Runtime protections, allowing attackers to inject malicious dynamic libraries into the application process. Successful exploitation granted attackers access to all Transparency, Consent, and Control (TCC) permissions assigned to the application.
Recommendations Update to version 2.3.7 or later.

Exploit

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2025-64723
GHSA-VF5J-XHWQ-8VQJ

Affected Products

Arduino Ide