CVE-2026-40599 Details
Description
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.5, ClearanceKit incorrectly treats a process with an empty Team ID and a non-empty Signing ID as an Apple platform binary. This bug allows a malicious software to impersonate an apple process in the global allowlist, and access all protected files. This vulnerability is fixed in 5.0.5.
A vulnerability in ClearanceKit prior to version 5.0.5 allows malicious software to impersonate Apple processes and bypass file access protections on macOS. The issue arises because ClearanceKit incorrectly identifies processes with an empty Team ID and a non-empty Signing ID as Apple platform binaries. This misclassification enables unauthorized access to protected files by exploiting the global allowlist for Apple processes.
Users should update to ClearanceKit version 5.0.5 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/craigjbass/clearancekit/security/advisories/GHSA-w253-42qp-5f2x | CISA-ADP | ExploitVendor Advisory |
| https://github.com/craigjbass/clearancekit/security/advisories/GHSA-w253-42qp-5f2x | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| craigjbass clearancekit | < 5.0.5 |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 24, 2026 | Initial Analysis | [email protected] |
| Apr 21, 2026 | CVE Modified | CISA-ADP |
| Apr 21, 2026 | New CVE Received | [email protected] |