Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Arduino IDE for macOS has TCC Bypass via Dynamic Library Injection
Vulnerability Description
Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS was configured with overly permissive security entitlements that could bypass macOS Hardened Runtime protections. This configuration allows attackers to inject malicious dynamic libraries into the application process, gaining access to all TCC (Transparency, Consent, and Control) permissions granted to the application. The fix is included starting from the `2.3.7 ` release.
CVSS Information
N/A
Vulnerability Type
缺省权限不正确
Vulnerability Title
Arduino IDE 安全漏洞
Vulnerability Description
Arduino IDE是Arduino开源的一个开发工具。 Arduino IDE 2.3.7之前版本存在安全漏洞,该漏洞源于安全权限配置不当,可能导致绕过macOS硬化运行时保护。
CVSS Information
N/A
Vulnerability Type
N/A