CVE-2025-69604
HIGHShirt-pocket Superduper! < 3.12 - Incorrect Default Permissions
Title source: ruleDescription
An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with root privileges and Full Disk Access, thus bypassing macOS privacy controls.
Exploits (1)
Scores
CVSS v3
7.8
EPSS
0.0002
EPSS Percentile
3.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-276
Status
published
Products (1)
shirt-pocket/superduper\!
< 3.12
Published
Jan 29, 2026
Tracked Since
Feb 18, 2026