File System Access Vulnerability in ClearanceKit for macOS
CVE-2026-40599
8.4HIGH
What is CVE-2026-40599?
ClearanceKit, a tool used for intercepting file-system access on macOS, has a vulnerability involving erroneous handling of process identification. Prior to version 5.0.5, it allowed processes with an empty Team ID but a non-empty Signing ID to be recognized as Apple binaries. This flaw enables malicious actors to masquerade as trusted Apple processes in the system's global allowlist, granting unauthorized access to all secured files. The vulnerability is addressed in version 5.0.5, highlighting the importance of keeping software updated to ensure robust security.
Affected Version(s)
clearancekit < 5.0.5
