PT-2026-61731 · Unknown · Clearancekit
CVE-2026-47133
·
Published
2026-07-20
·
Updated
2026-07-21
CVSS v4.0
6.9
Medium
| Vector | AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
ClearanceKit versions prior to 5.0.10
Description
ClearanceKit enforces per-process access policies by intercepting file-system access events on macOS. The software uses an on-disk SQLite policy store located at
/Library/Application Support/clearancekit/store.db, where tables are verified using ECDSA signatures stored in the data signatures table. Because the signed payload lacks a version counter or freshness binding, an attacker with write access to store.db and the data signatures row can perform a replay attack by substituting a previously captured, legitimately signed snapshot. This is possible during the opfilter-update window when the Endpoint Security filter is offline, or through offline-boot and decrypted-backup scenarios. The opfilter accepts the older snapshot as valid upon the next boot since the signatures remain valid.Recommendations
Update to version 5.0.10.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clearancekit