File-System Access Interception Issue in ClearanceKit by Craig J. Bass
CVE-2026-47133

6.9MEDIUM

Key Information:

Vendor

Craigjbass

Vendor
CVE Published:
20 July 2026

What is CVE-2026-47133?

ClearanceKit, a tool designed to enforce per-process access policies on macOS, has a vulnerability that affects its file-system access interception capabilities. Prior to version 5.0.10, the software does not properly bind version information to the ECDSA signatures stored in its SQLite policy database. This oversight allows an attacker with the ability to modify the store.db database to replace legitimate signed entries with previously captured snapshots, which the system accepts as valid upon boot. The flaw is particularly exploitable during specific operational windows when the Endpoint Security filter is offline, or through scenarios involving offline-boot or decrypted backup access. Version 5.0.10 addresses this weakness effectively.

Affected Version(s)

clearancekit < 5.0.10

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.