← back
CVE-2025-11921highCWE-732CWE-77

iStat Menus 7.10.4 - Local Privilege Escalation

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.5epss 0.6%
exploitation probability
0.6%top 52% of all CVEs
observed exploitation
nono source reports it
iStats contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via command injection.This issue affects iStats: 7.10.4.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Bjango · iStats