PT-2026-5345 · Shirt Pocket · Superduper!

Published

2026-01-29

·

Updated

2026-01-29

·

CVE-2025-69604

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SuperDuper! versions 3.11 and earlier
Description An issue allows a local attacker to modify the default task template to install an arbitrary package. This package can run shell scripts with root privileges and Full Disk Access, bypassing macOS privacy controls.
Recommendations Update to a version later than 3.11.

Fix

LPE

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2025-69604

Affected Products

Superduper!