PT-2026-61732 · Unknown · Clearancekit

CVE-2026-47134

·

Published

2026-07-20

·

Updated

2026-07-21

CVSS v4.0

6.9

Medium

VectorAV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions ClearanceKit versions prior to 5.0.10
Description ClearanceKit enforces per-process access policies by intercepting file-system access events on macOS. The software uses an ECDSA private key stored in the macOS System Keychain to sign the on-disk policy database located at /Library/Application Support/clearancekit/store.db. Due to a flaw in how the key is persisted using SecKeyCreateRandomKey and SecItemAdd(kSecValueRef:, kSecAttrAccess:), the kSecAttrAccess attribute is ignored for kSecClassKey items in the legacy System Keychain. This results in the persisted key lacking Access Control List (ACL) restrictions, allowing any process running with root privileges to use the key to create valid signatures for arbitrary policy content.
Recommendations Update to version 5.0.10. As a temporary mitigation, disable the system extension and manually remove the System Keychain item labeled clearancekit policy signing key, although this will disable policy enforcement.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47134

Affected Products

Clearancekit