VYPR

Superduper

by GreatWhiteShark

CVEs (2)

  • CVE-2025-69604Jan 29, 2026
    risk 0.00cvss epss 0.00

    An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with root privileges and Full Disk Access, thus bypassing macOS privacy controls.

  • CVE-2025-61229Dec 1, 2025
    risk 0.00cvss epss 0.00

    An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight script with root privileges and Full Disk Access, thus bypassing macOS privacy controls.