PT-2026-34037 · Unknown · Clearancekit
Published
2026-04-21
·
Updated
2026-04-21
·
CVE-2026-40599
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ClearanceKit versions prior to 5.0.5
Description
ClearanceKit intercepts file-system access events on macOS to enforce per-process access policies. A flaw exists where the software incorrectly identifies a process as an Apple platform binary if it possesses an empty Team ID and a non-empty Signing ID. This allows malicious software to impersonate an Apple process within the global allowlist to gain access to all protected files.
Recommendations
Update to version 5.0.5.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clearancekit