CVE-2025-11921
CVE-2025-11921
8.5
HighPublished:
Last updated:
Source:help@fluidattacks.com
Deferred
CVSS Vector
v4.0- Attack Vector
- Local
- Attack Complexity
- Low
- Attack Requirements
- None
- Privileges Required
- Low
- User Interaction
- None
- Confidentiality (Vulnerable)
- High
- Integrity (Vulnerable)
- High
- Availability (Vulnerable)
- High
- Confidentiality (Subsequent)
- None
- Integrity (Subsequent)
- None
- Availability (Subsequent)
- None
Description
iStats contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via command injection.This issue affects iStats: 7.10.4.
References
help@fluidattacks.com
https://bjango.com/mac/istatmenus/help@fluidattacks.com
https://cdn.istatmenus.app/files/istatmenus7/versions/iStatMenus7.10.6.ziphelp@fluidattacks.com
https://fluidattacks.com/advisories/muse