Executive brief
A security vulnerability exists in the Trend Micro Apex One agent for macOS, which is used to protect corporate endpoints from malware and threats. A local user with limited access to a computer could exploit this flaw to gain full administrative (root) control over the system. This could allow an attacker to bypass security controls, access sensitive data, or disable the security software entirely.
Technical details
An origin validation error exists within the iCore service of the Trend Micro Apex One (mac) agent. The vulnerability stems from the service's failure to properly validate the origin of Inter-Process Communication (IPC) messages. A local attacker who has already gained low-privileged code execution on the system can send crafted IPC messages to the iCore service to execute arbitrary code with root privileges. The issue was addressed in mid-to-late 2025 via ActiveUpdate and SaaS updates (SaaS 2507 & 2005 Yearly Release).
Affected products
- Trend Micro Apex One (mac) agent SaaS versions prior to 2507 and 2005 Yearly Release
Timeline
- 2025-03-30: disclosed: Vulnerability reported to vendor
- 2025-07-01: patched: Addressed via SaaS 2507 and 2005 Yearly Release updates
- 2026-03-03: advisory: Coordinated public release of advisory by ZDI
- 2026-05-21: other: NVD publication date