Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-23746


Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in some environments (bypass a kTCCServiceSystemPolicyAppBundles requirement via a file copy, an app.app/Contents rename, an asar modification, and a rename back to app.app/Contents).


Published

2024-02-02T02:15:18.330

Last Modified

2025-06-04T16:15:32.800

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-94
  • Type: Secondary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application miro miro 0.8.18 Yes
Operating System apple macos - No

References