CVE-2025-4412

On macOS systems, by utilizing a Launch Agent and loading the viscosity_openvpn process from the application bundle, it is possible to load a dynamic library with Viscosity's TCC (Transparency, Consent, and Control) identity. The acquired resource access is limited without entitlements such as access to the camera or microphone. Only user-granted permissions for file resources apply. Access to other resources beyond granted-permissions requires user interaction with a system prompt asking for permission. This issue was fixed in version 1.11.5 of Viscosity.
CVSS

No CVSS.

Configurations

No configuration.

History

28 May 2025, 15:01

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-27 10:15

Updated : 2025-05-28 15:01


NVD link : CVE-2025-4412

Mitre link : CVE-2025-4412

CVE.ORG link : CVE-2025-4412


JSON object : View

Products Affected

No product.

CWE
CWE-276

Incorrect Default Permissions