Executive brief
Mattermost Desktop App is a communication and collaboration platform client for Windows, Mac, and Linux. Versions up to 5.10.0 contain improperly configured system permissions on macOS that allow an attacker with remote code execution to bypass macOS security controls (Transparency, Consent, and Control), potentially accessing sensitive system resources without user authorization.
Technical details
The vulnerability is a privilege escalation / security bypass (CWE-426) stemming from the Desktop App explicitly declaring unnecessary macOS entitlements. An attacker with remote code execution capability can inject code into the application, which then executes with the elevated privileges granted by these overly-broad entitlements, thereby circumventing macOS TCC protections. The attack requires prior code execution within the app but allows bypass of system-level access controls. The vulnerability affects Mattermost Desktop App versions ≤5.10.0 and is fixed in version 5.11.0.
Affected products
- Mattermost Desktop App ≤5.10.0
Timeline
- 2025-03-17: disclosed
- 2025-03-17: patched: Fixed in version 5.11.0