High severity7.8NVD Advisory· Published Jan 29, 2026· Updated Jul 5, 2026
CVE-2025-69604
CVE-2025-69604
Description
An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with root privileges and Full Disk Access, thus bypassing macOS privacy controls.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:shirt-pocket:superduper\!:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:shirt-pocket:superduper\!:*:*:*:*:*:*:*:*range: <3.12
- (no CPE)
- (no CPE)range: <=3.11
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.