Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-47134— ClearanceKit: Policy signing key in System Keychain has permissive ACL allowing any local-root process to forge signed policy

AI Predicted 9.8 Difficulty: Moderate EPSS 0.11% · P1

Affected Version Matrix 1

VendorProductVersion RangeStatus
craigjbassclearancekit< 5.0.10affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-47134

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ClearanceKit: Policy signing key in System Keychain has permissive ACL allowing any local-root process to forge signed policy
Source: CVE Program / CVE List V5
Vulnerability Description
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. The ECDSA private key used to sign the on-disk policy database (`/Library/Application Support/clearancekit/store.db`) is stored in the macOS System Keychain. The key was created via the two-step pattern `SecKeyCreateRandomKey` (in-memory) followed by `SecItemAdd(kSecValueRef:, kSecAttrAccess:)` (persist). Prior to version 5.0.10, for `kSecClassKey` items in the legacy System Keychain, `kSecAttrAccess` passed to `SecItemAdd` is silently ignored — the persisted key inherits no ACL restriction. The same access builder applied to `kSecClassGenericPassword` items correctly binds the ACL, making this bug specific to the EC key. The result is that any process running as root can use the key to produce valid signatures over arbitrary policy content. Version 5.0.10 fixes the issue. No known workarounds are available. Disabling the system extension and manually removing the System Keychain item labelled `clearancekit policy signing key` would prevent the forged-signature path but also disables policy enforcement.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
关键资源的不正确权限授予
Source: CVE Program / CVE List V5
Vulnerability Title
Craig J. Bass ClearanceKit 权限许可和访问控制问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Craig J. Bass ClearanceKit是Craig J. Bass个人开发者开源的一个macOS文件系统访问控制工具。 Craig J. Bass ClearanceKit 5.0.10之前版本存在权限许可和访问控制问题漏洞,该漏洞源于ECDSA私钥在存储时忽略了ACL限制,可能导致任何以root身份运行的进程使用该密钥对任意策略内容生成有效签名。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
craigjbassclearancekit < 5.0.10 -

II. Public POCs for CVE-2026-47134

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-47134

登录查看更多情报信息。

Vendor Advisories for CVE-2026-47134 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-47134

No comments yet


Leave a comment