CVE-2025-70341

HIGH

App-Auto-Patch 3.4.2 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-70341. PoCs published by malvector.

AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2025-70341, which leverages a TOCTOU race condition in App-Auto-Patch due to world-writable directory permissions and unsanitized `eval` usage in Installomator label parsing. The PoC demonstrates local privilege escalation by swapping a verified PKG with a malicious one, achieving arbitrary code execution as root.

Description

Insecure permissions in App-Auto-Patch v3.4.2 create a race condition which allows attackers to write arbitrary files.

Exploits (1)

nomisec WORKING POC
by malvector · poc
https://github.com/malvector/CVE-2025-70341

This repository contains a functional proof-of-concept exploit for CVE-2025-70341, which leverages a TOCTOU race condition in App-Auto-Patch due to world-writable directory permissions and unsanitized `eval` usage in Installomator label parsing. The PoC demonstrates local privilege escalation by swapping a verified PKG with a malicious one, achieving arbitrary code execution as root.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Racy
Target: App-Auto-Patch <= 3.4.2
No auth needed
Prerequisites: macOS system with App-Auto-Patch <= 3.4.2 · unprivileged local user account · Xcode command line tools
devstral-2 · analyzed May 04, 2026 Full analysis →

Scores

CVSS v3 7.8
EPSS 0.0022
EPSS Percentile 11.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-94 CWE-732
Status published
Products (1)
app-auto-patch/app-auto-patch < 3.4.2
Published Mar 04, 2026
Tracked Since Mar 04, 2026