Security Vulnerability in Arduino IDE for macOS
CVE-2025-64723

4.8MEDIUM

Key Information:

Vendor

Arduino

Vendor
CVE Published:
18 December 2025

What is CVE-2025-64723?

The Arduino IDE for macOS, prior to version 2.3.7, is vulnerable due to its overly permissive security entitlements. This misconfiguration allows attackers to inject malicious dynamic libraries into the application process, which can circumvent macOS's Hardened Runtime protections. Through this vulnerability, unauthorized users can gain access to all Transparency, Consent, and Control (TCC) permissions that the application has been granted. The issue has been addressed in the 2.3.7 release, which secures the environment against such attacks.

Affected Version(s)

arduino-ide < 2.3.7

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-64723 : Security Vulnerability in Arduino IDE for macOS