CVE-2026-40604 Details
Description
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.6, the opfilter Endpoint Security system extension (bundle ID uk.craigbass.clearancekit.opfilter) can be suspended with SIGSTOP or kill -STOP, or killed with SIGKILL/SIGTERM, by any process running as root. While the extension is suspended, all AUTH Endpoint Security events time out and default to allow, silently disabling ClearanceKit's file-access policy enforcement for the duration of the suspension. This vulnerability is fixed in 5.0.6.
A vulnerability exists in ClearanceKit versions prior to 5.0.6, specifically within the 'opfilter' Endpoint Security system extension. This extension can be suspended or terminated by any process with root privileges, effectively disabling ClearanceKit's file-access policy enforcement. During the suspension, all AUTH Endpoint Security events are allowed by default, creating a window where unauthorized file-access operations can occur. This vulnerability could be exploited to bypass ClearanceKit's protections, allowing access to files that would normally be restricted or enabling the execution of blocked binaries.
Users can update to ClearanceKit version 5.0.6 or later, where this vulnerability has been fixed. Instructions for updating can be found in the ClearanceKit repository on GitHub.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/craigjbass/clearancekit/security/advisories/GHSA-5r9w-9fg6-266q | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-693 | Protection Mechanism Failure | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| craigjbass clearancekit | < 5.0.6 |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 24, 2026 | Initial Analysis | [email protected] |
| Apr 21, 2026 | New CVE Received | [email protected] |