Junglewise Threat Intelligence

CVE-2024-36287: Mattermost Desktop App TCC bypass on macOS

CVE-2024-36287 · Severity: low · CVSS 3.1 · Published 2024-06-14

Technologies: Mattermost Desktop App. Vendors: Mattermost.

Executive brief

Mattermost Desktop App on macOS failed to disable certain debug flags in Electron, allowing local attackers to bypass macOS Transparency, Consent, and Control (TCC) restrictions. This could permit unauthorized access to user data like camera, microphone, contacts, or files that the operating system is designed to protect through user consent prompts.

Technical details

The vulnerability stems from CWE-693 (Protection Mechanism Failure) where Mattermost Desktop App versions ≤5.7.0 left Electron debug flags enabled in the production build. These debug flags can be leveraged by a local attacker with user-level privileges to bypass macOS TCC (Transparency, Consent, and Control) restrictions without user interaction. An attacker with local access to the system running the affected application can exploit this to gain unauthorized access to protected resources. The vulnerability was fixed in version 5.8.0.

Affected products

  • Mattermost Desktop App 5.7.0 and earlier

Timeline

  • 2024-06-14: disclosed: Vulnerability published
  • 2024-06-14: patched: Fix available in version 5.8.0

References

Related threats