Junglewise Threat Intelligence

CVE-2025-69604: Shirt Pocket SuperDuper! privilege escalation via task templates

CVE-2025-69604 · Severity: high · CVSS 7.8 · Published 2026-01-29

Technologies: Shirt-Pocket Superduper\!. Vendors: Shirt-Pocket.

Executive brief

SuperDuper! is a backup and disk cloning utility for macOS. A security vulnerability in versions 3.11 and earlier allows a local user to modify backup task templates to install malicious software packages. If exploited, an attacker could gain full control over the computer with root privileges and bypass macOS privacy protections, potentially leading to total data exposure or system takeover.

Technical details

A vulnerability classified as Incorrect Default Permissions (CWE-276) exists in Shirt Pocket SuperDuper! versions 3.11 and earlier. The application's task template system allows a local attacker to modify settings to include an arbitrary installer package. Because SuperDuper! executes these packages with root privileges and Full Disk Access to facilitate system updates, an attacker can run malicious shell scripts that bypass macOS Transparency, Consent, and Control (TCC) privacy frameworks. The vendor addressed this in version 3.12 by completely removing the package installation feature from the Advanced options tab.

Affected products

  • Shirt Pocket SuperDuper! 3.11 and earlier

Timeline

  • 2025-01-29: disclosed
  • 2026-01-29: advisory: NVD publication date
  • 2026-01-29: patched: Version 3.12 released

References

Related threats