CVE-2026-12374 Details
Description
Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC service in Cato Client before v.5.13.1 on macOS allows a local authenticated attacker to escalate privileges to root via a self-signed certificate that bypasses the XPC caller verification and a symlink swap during package installation.
A vulnerability in the PrivilegedHelperTool XPC service of Cato Client for macOS, prior to version 5.13.1, allows local authenticated attackers to escalate privileges to root. This issue arises from improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition, which can be exploited using a self-signed certificate that bypasses XPC caller verification, combined with a symlink swap during package installation.
Users can update to Cato Client version 5.13.1 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 1, 2026CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.catonetworks.com/hc/en-us/articles/37284626576413-Security-Vulnerability-CVE-2026-12374-that-Impacts-macOS-Client-Versions-Lower-than-5-13-1 | Cato | AdvisoryPermission RequiredVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | Cato |
| CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition | Cato |
Affected Products
| Product | Versions |
|---|---|
| Cato Client | < 5.13.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jul 1, 2026 | New CVE Received | Cato |
Volerion