File-System Access Interception Issue in ClearanceKit by Craig J. Bass
CVE-2026-47133
What is CVE-2026-47133?
ClearanceKit, a tool designed to enforce per-process access policies on macOS, has a vulnerability that affects its file-system access interception capabilities. Prior to version 5.0.10, the software does not properly bind version information to the ECDSA signatures stored in its SQLite policy database. This oversight allows an attacker with the ability to modify the store.db database to replace legitimate signed entries with previously captured snapshots, which the system accepts as valid upon boot. The flaw is particularly exploitable during specific operational windows when the Endpoint Security filter is offline, or through scenarios involving offline-boot or decrypted backup access. Version 5.0.10 addresses this weakness effectively.
Affected Version(s)
clearancekit < 5.0.10
