Home

Description

An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with root privileges and Full Disk Access, thus bypassing macOS privacy controls.

PUBLISHED Reserved 2026-01-09 | Published 2026-01-29 | Updated 2026-02-03 | Assigner mitre

References

shirt.com

shirt-pocket.com/SuperDuper/SuperDuperDescription.html

www.shirtpocket.com/...omments/superduper_v312_now_available

cve.org (CVE-2025-69604)

nvd.nist.gov (CVE-2025-69604)

Download JSON