Local Debugger Access Vulnerability in MacVim on macOS
CVE-2025-8597

4.8MEDIUM

Key Information:

Vendor

Macvim

Status
Vendor
CVE Published:
26 August 2025

What is CVE-2025-8597?

A configuration flaw in MacVim on macOS allows local attackers with unprivileged access to attach debuggers, altering or reading process memory and injecting code within the application context. This vulnerability exploits the 'com.apple.security.get-task-allow' entitlement, bypassing the typical user permission prompts required for greater access. Attackers can utilize this flaw through malicious applications, gaining access to resources previously permitted by the user, while other permissions necessitate user interaction. This issue was rectified in build r181.2.

Affected Version(s)

MacVim MacOS 0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Karol Mazurek - AFINE Team
.
CVE-2025-8597 : Local Debugger Access Vulnerability in MacVim on macOS