Security Advisory

CVE-2025-69604

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-01-29 00:00:00
Last updated 2026-07-05 01:28:09
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with root privileges and Full Disk Access, thus bypassing macOS privacy controls.