Junglewise Threat Intelligence

CVE-2025-61228: Shirt Pocket SuperDuper! code execution via software update mechanism

CVE-2025-61228 · Severity: high · CVSS 7.8 · Published 2025-12-01

Technologies: Shirt-Pocket Superduper\!. Vendors: Shirt-Pocket.

Executive brief

Shirt Pocket SuperDuper!, a popular backup and disk cloning utility for macOS, contains a vulnerability in its software update mechanism. A local attacker or malicious software already on the system could hijack the update process to install a fraudulent package instead of the legitimate software. If successful, this allows the attacker to gain full administrative control over the computer, potentially leading to data theft or complete system compromise.

Technical details

A vulnerability classified as CWE-494 (Download of Code Without Integrity Check) exists in Shirt Pocket SuperDuper! versions 3.10 and earlier. The software's auto-update mechanism fails to verify the signature and notarization of downloaded installer packages before execution. Because the macOS package installer runs with escalated privileges, a local attacker or malicious process can intercept the update request and substitute a malicious package. An exploit requires a legitimate update to be available and the user to trigger the 'Upgrade' process. The issue is resolved in version 3.11, which implements manual signature and notarization validation before installation.

Affected products

  • Shirt Pocket SuperDuper! 3.10 and earlier

Timeline

  • 2025-11-18: advisory: Vendor blog post detailing the vulnerability and release of v3.11
  • 2025-11-18: patched: Version 3.11 released to address the flaw
  • 2025-12-01: disclosed: CVE-2025-61228 published

References

Related threats