Executive brief
A security vulnerability exists in the Trend Micro Apex One agent for macOS, which is used to protect corporate endpoints from malware and threats. A local user with limited access could exploit a flaw in how the software handles its internal cache to gain full administrative (root) control over the computer. This could allow an attacker to bypass security controls, access sensitive data, or disable security monitoring.
Technical details
A Time-of-Check Time-of-Use (TOCTOU) race condition exists within the cache mechanism of the Trend Micro Apex One (mac) Security Agent. The vulnerability stems from a lack of proper cache key validation during signature verification processes. A local attacker with low-privileged code execution capabilities can exploit this flaw to manipulate the cache, leading to arbitrary code execution with root privileges. The issue was addressed in the SaaS 2507 and 2005 Yearly Release updates via ActiveUpdate.
Affected products
- Trend Micro Apex One (mac) Agent SaaS versions prior to 2507 and 2005 Yearly Release
Timeline
- 2025-04-08: disclosed: Vulnerability reported to vendor
- 2025-07-01: patched: Addressed in SaaS 2507 and 2005 Yearly Release updates
- 2026-03-03: advisory: ZDI advisory published
- 2026-05-21: advisory: NVD publication date