PT-2026-28501 · Unknown · Clearancekit
Published
2026-03-26
·
Updated
2026-03-26
·
CVE-2026-33632
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ClearanceKit versions prior to 4.2.4
Description
ClearanceKit monitors file system access events on macOS and enforces access policies on a per-process basis. Before version 4.2.4, two file operation event types—
ES EVENT TYPE AUTH EXCHANGEDATA and ES EVENT TYPE AUTH CLONE—were not intercepted by ClearanceKit’s opfilter system extension. This allowed local processes to bypass file access policies. The issue was addressed in commit 6181c4a by subscribing to both event types and routing them through the existing policy evaluator.Recommendations
Upgrade to version 4.2.4 or later and reactivate the system extension.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clearancekit