High severity7.8NVD Advisory· Published Jan 6, 2026· Updated Apr 9, 2026
CVE-2025-14979
CVE-2025-14979
Description
AirVPN Eddie on MacOS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.This issue affects Eddie: 2.24.6.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- fluidattacks.com/advisories/blink182nvdExploitThird Party Advisory
- airvpn.org/forums/topic/79305-eddie-desktop-edition-225-beta-released/nvdIssue TrackingRelease Notes
- eddie.websitenvdProduct
News mentions
0No linked articles in our index yet.