Executive brief
Mattermost Desktop App on macOS failed to disable certain debug flags in Electron, allowing local attackers to bypass macOS Transparency, Consent, and Control (TCC) restrictions. This could permit unauthorized access to user data like camera, microphone, contacts, or files that the operating system is designed to protect through user consent prompts.
Technical details
The vulnerability stems from CWE-693 (Protection Mechanism Failure) where Mattermost Desktop App versions ≤5.7.0 left Electron debug flags enabled in the production build. These debug flags can be leveraged by a local attacker with user-level privileges to bypass macOS TCC (Transparency, Consent, and Control) restrictions without user interaction. An attacker with local access to the system running the affected application can exploit this to gain unauthorized access to protected resources. The vulnerability was fixed in version 5.8.0.
Affected products
- Mattermost Desktop App 5.7.0 and earlier
Timeline
- 2024-06-14: disclosed: Vulnerability published
- 2024-06-14: patched: Fix available in version 5.8.0