Executive brief
Trend Micro Apex One is an enterprise security platform used to protect endpoints from malware and other threats. A vulnerability in the macOS agent's core service could allow a user who already has limited access to the computer to gain full administrative (root) control. This could allow an attacker to bypass security settings, access sensitive data, or disable the security software entirely.
Technical details
A Time-of-Check Time-of-Use (TOCTOU) vulnerability exists in the iCore service of the Trend Micro Apex One (mac) agent. The flaw is rooted in the lack of proper file path validation during the signature verification process. A local attacker with low-privileged code execution capabilities can exploit this race condition to swap a verified file with a malicious one between the time the service checks the signature and the time it uses the file. Successful exploitation allows the attacker to execute arbitrary code with root privileges. The issue has been addressed in SaaS updates (SaaS 2507 & 2005 Yearly Release) and via ActiveUpdate.
Affected products
- Trend Micro Apex One (mac) agent SaaS versions prior to 2507 and 2005 Yearly Release
Timeline
- 2025-04-08: disclosed: Vulnerability reported to vendor
- 2025-07: patched: Addressed in SaaS 2507 and 2005 Yearly Release via ActiveUpdate
- 2026-03-03: advisory: Coordinated public release by ZDI
- 2026-05-21: other: NVD publication date