PT-2026-29276 · Craigjbass+1 · Clearancekit
Craigjbass
·
Published
2026-03-31
·
Updated
2026-03-31
·
CVE-2026-34218
CVSS v4.0
6.3
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
ClearanceKit versions prior to 4.2.14
Description
ClearanceKit intercepts file-system access events on macOS to enforce per-process access policies. Startup defects create a window where only the compile-time baseline rule is enforced by opfilter. During this period, user-defined and managed (MDM-delivered) file-access rules are not applied until a policy mutation over XPC is triggered by the user interacting with policies through the GUI.
Recommendations
Update to version 4.2.14.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clearancekit