Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
ClearanceKit: Policy signing key in System Keychain has permissive ACL allowing any local-root process to forge signed policy
Vulnerability Description
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. The ECDSA private key used to sign the on-disk policy database (`/Library/Application Support/clearancekit/store.db`) is stored in the macOS System Keychain. The key was created via the two-step pattern `SecKeyCreateRandomKey` (in-memory) followed by `SecItemAdd(kSecValueRef:, kSecAttrAccess:)` (persist). Prior to version 5.0.10, for `kSecClassKey` items in the legacy System Keychain, `kSecAttrAccess` passed to `SecItemAdd` is silently ignored — the persisted key inherits no ACL restriction. The same access builder applied to `kSecClassGenericPassword` items correctly binds the ACL, making this bug specific to the EC key. The result is that any process running as root can use the key to produce valid signatures over arbitrary policy content. Version 5.0.10 fixes the issue. No known workarounds are available. Disabling the system extension and manually removing the System Keychain item labelled `clearancekit policy signing key` would prevent the forged-signature path but also disables policy enforcement.
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N
Vulnerability Type
关键资源的不正确权限授予
Vulnerability Title
Craig J. Bass ClearanceKit 权限许可和访问控制问题漏洞
Vulnerability Description
Craig J. Bass ClearanceKit是Craig J. Bass个人开发者开源的一个macOS文件系统访问控制工具。 Craig J. Bass ClearanceKit 5.0.10之前版本存在权限许可和访问控制问题漏洞,该漏洞源于ECDSA私钥在存储时忽略了ACL限制,可能导致任何以root身份运行的进程使用该密钥对任意策略内容生成有效签名。
CVSS Information
N/A
Vulnerability Type
N/A