In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker to escalate privileges by modifying files executed with administrative privileges by a Launch Daemon during system startup.
2025-07-12T00:15:23.460
2025-08-26T18:37:22.187
Analyzed
CVSSv3.1: 7.3 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | canonical | multipass | < 1.16.0 | Yes |
Operating System | apple | macos | - | No |