CVE-2025-34089

CRITICAL

Remote for Mac <= 2025.7 - Unauthenticated Remote Code Execution via X-Script Header

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-34089. PoCs published by Chokri Hammedi (@blue0x1), including Metasploit module exploits/osx/http/remote_for_mac_rce.

AI-analyzed exploit summary This Metasploit module exploits an unauthenticated RCE vulnerability in Remote for Mac via the /api/executeScript endpoint, allowing arbitrary AppleScript execution, including shell commands. It checks the target version and delivers a reverse shell payload if the system is vulnerable.

Description

An unauthenticated remote code execution vulnerability exists in Remote for Mac, a macOS remote control utility developed by Aexol Studio, in versions up to and including 2025.7. When the application is configured with authentication disabled (i.e., the "Allow unknown devices" option is enabled), the /api/executeScript endpoint is exposed without access control. This allows unauthenticated remote attackers to inject arbitrary AppleScript payloads via the X-Script HTTP header, resulting in code execution using do shell script. Successful exploitation grants attackers the ability to run arbitrary commands on the macOS host with the privileges of the Remote for Mac background process.

Exploits (1)

metasploit WORKING POC NORMAL
by Chokri Hammedi (@blue0x1) · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/osx/http/remote_for_mac_rce.rb

This Metasploit module exploits an unauthenticated RCE vulnerability in Remote for Mac via the /api/executeScript endpoint, allowing arbitrary AppleScript execution, including shell commands. It checks the target version and delivers a reverse shell payload if the system is vulnerable.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Remote for Mac versions up to and including 2025.7
No auth needed
Prerequisites: Target system with Remote for Mac <= 2025.7 · Authentication disabled on /api/executeScript
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v4 9.3
EPSS 0.0139
EPSS Percentile 68.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-306 CWE-94
Status published
Products (1)
Aexol Studio/Remote for Mac < 2025.7
Published Jul 03, 2025
Tracked Since Feb 18, 2026