PT-2025-52245 · Arduino · Arduino Ide

Karmaz95

+1

·

Published

2025-12-18

·

Updated

2026-02-19

·

CVE-2025-64724

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Arduino IDE versions prior to 2.3.7
Description Arduino IDE for macOS, before version 2.3.7, was installed with overly permissive file permissions on critical application components. This allowed any local user to replace legitimate files with malicious code. When another user launched the application, the malicious code would execute with their privileges, potentially leading to privilege escalation and unauthorized access to sensitive data.
Recommendations Update to version 2.3.7 or later.

Exploit

Fix

LPE

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2025-64724
GHSA-3FVJ-PGQW-FGW6

Affected Products

Arduino Ide