Unrated severityNVD Advisory· Published Jul 11, 2025· Updated Jul 14, 2025
LPE on Multipass for macOS
CVE-2025-5199
Description
In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker to escalate privileges by modifying files executed with administrative privileges by a Launch Daemon during system startup.
Affected products
2- Canonical/Multipassv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/canonical/multipass/pull/4115mitrepatch
- github.com/canonical/multipass/security/advisories/GHSA-2j82-p5cq-62p3mitrevendor-advisory
News mentions
0No linked articles in our index yet.