An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight script with root privileges and Full Disk Access, thus bypassing macOS privacy controls.
References
Configurations
History
No history.
Information
Published : 2025-12-01 16:15
Updated : 2026-07-05 02:17
NVD link : CVE-2025-61229
Mitre link : CVE-2025-61229
CVE.ORG link : CVE-2025-61229
JSON object : View
Products Affected
shirt-pocket
- superduper\!
