CVE-2026-47134 Details
Description
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. The ECDSA private key used to sign the on-disk policy database (`/Library/Application Support/clearancekit/store.db`) is stored in the macOS System Keychain. The key was created via the two-step pattern `SecKeyCreateRandomKey` (in-memory) followed by `SecItemAdd(kSecValueRef:, kSecAttrAccess:)` (persist). Prior to version 5.0.10, for `kSecClassKey` items in the legacy System Keychain, `kSecAttrAccess` passed to `SecItemAdd` is silently ignored — the persisted key inherits no ACL restriction. The same access builder applied to `kSecClassGenericPassword` items correctly binds the ACL, making this bug specific to the EC key. The result is that any process running as root can use the key to produce valid signatures over arbitrary policy content. Version 5.0.10 fixes the issue. No known workarounds are available. Disabling the system extension and manually removing the System Keychain item labelled `clearancekit policy signing key` would prevent the forged-signature path but also disables policy enforcement.
A vulnerability in ClearanceKit prior to version 5.0.10 allows any process running as root to forge signatures on policy content. This issue arises because the ECDSA private key used for signing is stored in the macOS System Keychain without proper access controls, enabling unauthorized modification of the application's policy database. The vulnerability can be exploited by injecting arbitrary rules or disabling security features, bypassing existing signature verification processes.
Users can update to ClearanceKit version 5.0.10 or later, where this vulnerability has been fixed. Existing installations will automatically migrate to the patched version on first launch.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 20, 2026CISA-ADP
Assessed Jul 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/craigjbass/clearancekit/security/advisories/GHSA-w254-hxm5-3hgh | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-732 | Incorrect Permission Assignment for Critical Resource | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ClearanceKit | < 5.0.10 (semver) = 5.0.10-beta-eab3c5d (semver) = 5.0.10-beta-c1747fa (semver) = 5.0.10-beta-42fc946 (semver) = 5.0.10-beta-f7a57d6 (semver) = 5.0.10-beta-a7227fa (semver) = 5.0.10-beta-324dedc (semver) = 5.0.10-beta-b98d3cd (semver) = 5.0.10-beta-578aebc (semver) = 5.0.10-beta-e34820d (semver) = 5.0.10-beta-1ecf73c (semver) = 5.0.10-beta-f4fba42 (semver) = 5.0.10-beta-40894f9 (semver) = 5.0.10-beta-8e0a2e7 (semver) = 5.0.10-beta-5780b84 (semver) = 5.0.10-beta-b4b91e5 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Modified | CISA-ADP |
| Jul 20, 2026 | New CVE Received | [email protected] |
Volerion