Access Control Vulnerability in ClearanceKit on macOS by Craig J. Bass
CVE-2026-47134
6.9MEDIUM
What is CVE-2026-47134?
The ClearanceKit application for macOS implements file-system access event interceptions and enforces access policies on a per-process basis. A significant flaw exists in the handling of the ECDSA private key utilized for signing its policy database, where the access controls originally intended for secure key management are not applied properly due to a bug affecting legacy System Keychain items. This oversight allows any process with root privileges to utilize the exposed key for unauthorized signature generation over potentially harmful policy data. ClearanceKit version 5.0.10 addresses this vulnerability, but until then, the lack of defined access controls poses a significant risk.
Affected Version(s)
clearancekit < 5.0.10
