Executive brief
Shirt Pocket SuperDuper!, a popular backup and disk cloning utility for macOS, contains a vulnerability in its software update mechanism. A local attacker or malicious software already on the system could hijack the update process to install a fraudulent package instead of the legitimate software. If successful, this allows the attacker to gain full administrative control over the computer, potentially leading to data theft or complete system compromise.
Technical details
A vulnerability classified as CWE-494 (Download of Code Without Integrity Check) exists in Shirt Pocket SuperDuper! versions 3.10 and earlier. The software's auto-update mechanism fails to verify the signature and notarization of downloaded installer packages before execution. Because the macOS package installer runs with escalated privileges, a local attacker or malicious process can intercept the update request and substitute a malicious package. An exploit requires a legitimate update to be available and the user to trigger the 'Upgrade' process. The issue is resolved in version 3.11, which implements manual signature and notarization validation before installation.
Affected products
- Shirt Pocket SuperDuper! 3.10 and earlier
Timeline
- 2025-11-18: advisory: Vendor blog post detailing the vulnerability and release of v3.11
- 2025-11-18: patched: Version 3.11 released to address the flaw
- 2025-12-01: disclosed: CVE-2025-61228 published