CVE-2025-1398

Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.
References
Configurations

No configuration.

History

31 Mar 2025, 16:15

Type Values Removed Values Added
Summary
  • (es) Las versiones &lt;=5.10.0 de Mattermost Desktop App declararon explícitamente derechos innecesarios de macOS que permiten a un atacante con acceso remoto eludir la Transparencia, el Consentimiento y el Control (TCC) mediante la inyección de código.

17 Mar 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-17 15:15

Updated : 2025-03-31 16:15


NVD link : CVE-2025-1398

Mitre link : CVE-2025-1398

CVE.ORG link : CVE-2025-1398


JSON object : View

Products Affected

No product.

CWE
CWE-426

Untrusted Search Path