High severity7.1NVD Advisory· Published Apr 21, 2026· Updated Apr 24, 2026
CVE-2026-40599
CVE-2026-40599
Description
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.5, ClearanceKit incorrectly treats a process with an empty Team ID and a non-empty Signing ID as an Apple platform binary. This bug allows a malicious software to impersonate an apple process in the global allowlist, and access all protected files. This vulnerability is fixed in 5.0.5.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/craigjbass/clearancekit/security/advisories/GHSA-w253-42qp-5f2xnvdExploitVendor Advisory
News mentions
0No linked articles in our index yet.