Executive brief
ClearanceKit is a security tool for macOS that manages file access permissions for different applications. A vulnerability in how it stores its security rules allows an attacker with administrative access to replace current security settings with older, less restrictive versions. This could allow an attacker to bypass newer security protections or re-enable features that were previously disabled by the administrator.
Technical details
ClearanceKit (prior to version 5.0.10) uses an SQLite database to store per-process access policies, with integrity verified via ECDSA signatures in a 'data_signatures' table. However, the signed payload lacks a monotonic counter or timestamp (freshness binding). An attacker with local root privileges can exploit windows where the Endpoint Security filter is offline (such as during updates or via offline boot) to replace the current 'store.db' with a previously captured, legitimately-signed version. The system accepts the older snapshot as valid because the signatures remain cryptographically correct. This allows for the persistence of outdated or less-restrictive security policies. The issue is resolved in version 5.0.10 by introducing an 'epoch ratchet' stored in the System Keychain.
Affected products
- craigjbass ClearanceKit < 5.0.10
Timeline
- 2026-05-17: advisory: Vendor advisory published on GitHub
- 2026-07-20: disclosed: CVE published to NVD
- 2026-07-20: patched: Version 5.0.10 released to address the issue