HarborGuard / CVE
Back to search
HIGHCVE-2026-40599Published Modified CNA GitHub_M

CVE-2026-40599: ClearanceKit: Ad-hoc signed binaries can spoof Apple process identities in the global allowlist

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.5, ClearanceKit incorrectly treats a process with an empty Team ID and a non-empty Signing ID as an Apple platform binary. This bug allows a malicious software to impersonate an apple process in the global allowlist, and access all protected files. This vulnerability is fixed in 5.0.5.

Metrics

CVSS v4.0
8.4
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • craigjbass / clearancekit
    < 5.0.5
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N