Mattermost Desktop App fails to enable Hardened Runtime when packaged for Mac App Store
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 3.9epss 0.1%
exploitation probability
0.1%top 98% of all CVEs
observed exploitation
nono source reports it
Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit TCC permissions via copying the binary to a tmp folder.
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Affected products
Mattermost · MattermostReferences
https://mattermost.com/security-updates