CVE-2026-40604
MEDIUMClearanceKit: opfilter system extension can be suspended or signalled by a root process, disabling file-access policy enforcement
Title source: cnaDescription
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.6, the opfilter Endpoint Security system extension (bundle ID uk.craigbass.clearancekit.opfilter) can be suspended with SIGSTOP or kill -STOP, or killed with SIGKILL/SIGTERM, by any process running as root. While the extension is suspended, all AUTH Endpoint Security events time out and default to allow, silently disabling ClearanceKit's file-access policy enforcement for the duration of the suspension. This vulnerability is fixed in 5.0.6.
Scores
CVSS v3
4.4
EPSS
0.0002
EPSS Percentile
5.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-693
Status
published
Products (1)
craigjbass/clearancekit
< 5.0.6 (2 CPE variants)
Published
Apr 21, 2026
Tracked Since
Apr 21, 2026