First published: Mon Mar 17 2025(Updated: )
Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.
Credit: responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
npm/mattermost-desktop | <5.11.0 | 5.11.0 |
Mattermost | <=5.10.0 |
Update Mattermost Desktop App to versions 5.11.0 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-1398 is high due to its potential for remote code execution through the exploitation of unnecessary macOS entitlements.
To fix CVE-2025-1398, upgrade the Mattermost Desktop App to version 5.10.1 or later, which removes the unnecessary entitlements.
CVE-2025-1398 affects the Mattermost Desktop App versions 5.10.0 and earlier on macOS.
Yes, CVE-2025-1398 can be exploited remotely by an attacker with access to the affected system.
The impact of CVE-2025-1398 on user privacy is significant as it allows attackers to bypass macOS Transparency, Consent, and Control (TCC) mechanisms.