CVE-2024-36287: Bypass of TCC restrictions on macOS
Published Jun 14, 2024
·Updated
Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS.
Affected Software
3 affected componentsFixes available
npm/mattermost-desktop<5.8.0
5.8.0
All of the following
Mattermost Mattermost Desktop<=5.7.0
macOS
Remediation
Information
Update Mattermost Desktop App to versions 5.8.0 or higher.
Event History
Jun 14, 2024
CVE Published
via MITRE·08:39 AM
Data Sourced
via MITRE·08:39 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·09:31 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-36287?
CVE-2024-36287 is considered a high-severity vulnerability due to its potential to bypass TCC restrictions on macOS.
2
How do I fix CVE-2024-36287?
To fix CVE-2024-36287, upgrade to Mattermost Desktop App version 5.8.0 or later.
3
Which versions of Mattermost Desktop App are affected by CVE-2024-36287?
Mattermost Desktop App versions 5.7.0 and below are affected by CVE-2024-36287.
4
What are the implications of CVE-2024-36287?
CVE-2024-36287 allows malicious actors to bypass certain security measures on macOS, potentially compromising user data.
5
Is macOS vulnerable due to CVE-2024-36287?
No, macOS itself is not vulnerable; the issue lies within versions of the Mattermost Desktop App that fail to disable certain debug flags.