Privilege Escalation in Arduino IDE for macOS
CVE-2025-64724
What is CVE-2025-64724?
The Arduino IDE for macOS, before version 2.3.7, is susceptible to unauthorized file modification due to incorrect world-writable permissions on sensitive application components. This flaw allows any local user to replace legitimate application files with malicious code. When the compromised application is executed by another user, the malware runs with that user’s privileges, leading to potential privilege escalation and unauthorized access to sensitive information. Users are advised to update to version 2.3.7 or later to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
arduino-ide < 2.3.7
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
