CVE-2025-13326: Mattermost Desktop App fails to enable Hardened Runtime when packaged for Mac App Store
Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit TCC permissions via copying the binary to a tmp folder.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13326?
CVE-2025-13326 has a severity rating that indicates a moderate risk due to potential exploitation through inherited TCC permissions.
How do I fix CVE-2025-13326?
To fix CVE-2025-13326, upgrade the Mattermost Desktop App to version 6.0.0 or later where the Hardened Runtime is enabled.
What versions of the Mattermost Desktop App are affected by CVE-2025-13326?
CVE-2025-13326 affects all Mattermost Desktop App versions prior to 6.0.0.
What vulnerability does CVE-2025-13326 exploit?
CVE-2025-13326 exploits the lack of Hardened Runtime in the Mattermost Desktop App, allowing TCC permission inheritance.
How can I determine if my Mattermost Desktop App version is vulnerable to CVE-2025-13326?
Check your Mattermost Desktop App version against the version history; any version before 6.0.0 is vulnerable to CVE-2025-13326.