CVE-2026-12374: Improper XPC caller certificate validation and TOCTOU race condition in macOS PrivilegedHelperTool
Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC service in Cato Client before v.5.13.1 on macOS allows a local authenticated attacker to escalate privileges to root via a self-signed certificate that bypasses the XPC caller verification and a symlink swap during package installation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cato Client (macOS) PrivilegedHelperToolto a version that resolves this vulnerability.Fixed in 5.13.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12374?
CVE-2026-12374 has a medium severity rating of 6.4 on the CVSS scale.
How do I fix CVE-2026-12374?
To remediate CVE-2026-12374, upgrade the Cato Client to version 5.13.1 or later.
What type of attack does CVE-2026-12374 allow?
CVE-2026-12374 allows a local authenticated attacker to escalate privileges to root.
What causes the vulnerability in CVE-2026-12374?
CVE-2026-12374 is caused by improper XPC caller certificate validation and a TOCTOU race condition.
Which software is affected by CVE-2026-12374?
CVE-2026-12374 affects Cato Networks Cato Client versions prior to 5.13.1 on macOS.