Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.
References
History

Tue, 18 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Mar 2025 14:45:00 +0000

Type Values Removed Values Added
Description Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.
Title macOS TCC Bypass via Code Injection
Weaknesses CWE-426
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published: 2025-03-17T14:19:51.718Z

Updated: 2025-03-18T18:38:37.183Z

Reserved: 2025-02-17T15:58:13.659Z

Link: CVE-2025-1398

cve-icon Vulnrichment

Updated: 2025-03-18T18:38:33.392Z

cve-icon NVD

Status : Received

Published: 2025-03-17T15:15:43.243

Modified: 2025-03-17T15:15:43.243

Link: CVE-2025-1398

cve-icon Redhat

No data.