CVE-2025-1413 Details
Description
DaVinci Resolve on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent with standard macOS security practices, where applications should have drwxr-xr-x permissions. Incorrect permissions allow for Dylib Hijacking. Guest account, other users and applications can exploit this vulnerability for privilege escalation. This issue affects DaVinci Resolve on MacOS in versions before 19.1.3.
A vulnerability in Blackmagic DaVinci Resolve on macOS was identified, where the application was installed with overly permissive file rights (rwxrwxrwx). This permission setting deviates from standard macOS security norms, which dictate that applications should have drwxr-xr-x permissions. The excessive permissions create an opportunity for Dylib Hijacking, a technique that can be exploited by the guest account, other users, and applications to escalate privileges. This vulnerability affects all DaVinci Resolve versions on macOS prior to 19.1.3.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 28, 2025CISA-ADP
Assessed Feb 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://apps.apple.com/pl/app/davinci-resolve/id571213070?mt=12 | [email protected] | ProductVendor |
| https://cert.pl/en/posts/2025/02/CVE-2025-1413/ | [email protected] | AdvisoryVendor |
| https://cert.pl/posts/2025/02/CVE-2025-1413/ | [email protected] | AdvisoryVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-732 | Incorrect Permission Assignment for Critical Resource | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Blackmagic Design DaVinci Resolve | < 19.1.3 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 3, 2025 | CVE Modified | [email protected] |
| Mar 26, 2025 | CVE Modified | [email protected] |
| Feb 28, 2025 | New CVE Received | [email protected] |
Volerion