The ClearanceKit software has vulnerabilities that allow processes with an empty Team ID and non-empty Signing ID to be incorrectly treated as Apple platform binaries.
Claims
The ClearanceKit software has vulnerabilities that allow processes with an empty Team ID and non-empty Signing ID to be incorrectly treated as Apple platform binaries.
Parent: CybersecurityEntity: ClearanceKitImpact: negativeDate: Apr 21, 2026Target: The ClearanceKit software's handling of process identification
The ClearanceKit software has a vulnerability that allows the opfilter system extension to be suspended with SIGSTOP or kill commands, potentially compromising its security functionality.
Parent: CybersecurityEntity: ClearanceKitImpact: negativeDate: Apr 21, 2026Target: The ClearanceKit software's security mechanisms
Source posts
๐จ EUVD-2026-24209
๐ Score: 8.4/10 (CVSS v3.1)
๐ฆ Product: clearancekit
๐ข Vendor: craigjbass
๐
Updated: 2026-04-21
๐ ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.5, ClearanceKit incorrectly treats a process with an empty Team ID and a non-empty Signing ID as an Apple platform binary. This bug allo...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24209
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#euvd#cve#vulnerability#cybersecurity#infosec
๐จ EUVD-2026-24213
๐ Score: 8.2/10 (CVSS v3.1)
๐ฆ Product: clearancekit
๐ข Vendor: craigjbass
๐
Updated: 2026-04-21
๐ ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.6, the opfilter Endpoint Security system extension (bundle ID uk.craigbass.clearancekit.opfilter) can be suspended with SIGSTOP or kill ...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24213
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability