Home

Description

An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight script with root privileges and Full Disk Access, thus bypassing macOS privacy controls.

PUBLISHED Reserved 2025-09-26 | Published 2025-12-01 | Updated 2025-12-01 | Assigner mitre

References

shirt.com

shirt-pocket.com/SuperDuper/SuperDuperDescription.html

www.shirtpocket.com/...ents/superduper_security_update_v311/

cve.org (CVE-2025-61229)

nvd.nist.gov (CVE-2025-61229)

Download JSON