PT-2026-61731 · Unknown · Clearancekit

CVE-2026-47133

·

Published

2026-07-20

·

Updated

2026-07-21

CVSS v4.0

6.9

Medium

VectorAV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ClearanceKit versions prior to 5.0.10
Description ClearanceKit enforces per-process access policies by intercepting file-system access events on macOS. The software uses an on-disk SQLite policy store located at /Library/Application Support/clearancekit/store.db, where tables are verified using ECDSA signatures stored in the data signatures table. Because the signed payload lacks a version counter or freshness binding, an attacker with write access to store.db and the data signatures row can perform a replay attack by substituting a previously captured, legitimately signed snapshot. This is possible during the opfilter-update window when the Endpoint Security filter is offline, or through offline-boot and decrypted-backup scenarios. The opfilter accepts the older snapshot as valid upon the next boot since the signatures remain valid.
Recommendations Update to version 5.0.10.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47133

Affected Products

Clearancekit