An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with root privileges and Full Disk Access, thus bypassing macOS privacy controls.
References
| Link | Resource |
|---|---|
| http://shirt.com | Broken Link |
| https://shirt-pocket.com/SuperDuper/SuperDuperDescription.html | Product |
| https://www.shirtpocket.com/blog/index.php/shadedgrey/comments/superduper_v312_now_available | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-01-29 20:16
Updated : 2026-02-13 20:32
NVD link : CVE-2025-69604
Mitre link : CVE-2025-69604
CVE.ORG link : CVE-2025-69604
JSON object : View
Products Affected
shirt-pocket
- superduper\!
CWE
CWE-276
Incorrect Default Permissions
