CVE-2025-61228 Details
Description
An issue in Shirt Pocket SuperDuper! V.3.10 and before allows a local attacker to execute arbitrary code via the software update mechanism
A vulnerability allowing local attackers to execute arbitrary code has been identified in Shirt Pocket SuperDuper! versions through 3.10. This issue arises from the software update mechanism, which can be manipulated to install unauthorized packages. The vulnerability exploits the fact that, although the SuperDuper! installer package is signed and notarized, macOS's package installer does not verify this notarization, potentially allowing a malicious program to gain administrator access.
Users are advised to update to SuperDuper! version 3.11, which is available for download from the Shirt Pocket website. After updating, users should disable automatic updates in the SuperDuper! preferences to prevent the application from attempting to update to a vulnerable version.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-494 | Download of Code Without Integrity Check | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| shirt-pocket superduper! | <= 3.10 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 5, 2025 | Initial Analysis | [email protected] |
| Dec 1, 2025 | CVE Modified | CISA-ADP |
| Dec 1, 2025 | New CVE Received | [email protected] |