Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-5199


In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker to escalate privileges by modifying files executed with administrative privileges by a Launch Daemon during system startup.


Published

2025-07-12T00:15:23.460

Last Modified

2025-08-26T18:37:22.187

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.3 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-276
  • Type: Primary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application canonical multipass < 1.16.0 Yes
Operating System apple macos - No

References