← Volver a CVEs
CVE-2025-10906
HIGH8.4
Descripcion
A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS. This affects the function loadModuleNamed:WithReply of the file /Applications/Endurance.app/Contents/Library/LaunchServices/com.MagnetismStudios.endurance.helper of the component NSXPC Interface. Executing manipulation can lead to missing authentication. The attack needs to be launched locally. The exploit has been published and may be used.
Detalles CVE
Puntuacion CVSS v3.18.4
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueLOCAL
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado9/24/2025
Ultima modificacion4/29/2026
Fuentenvd
Avistamientos honeypot0
Debilidades (CWE)
CWE-287CWE-306
Referencias
https://github.com/SwayZGl1tZyyy/n-days/blob/main/Endurance/README.md#proof-of-concept(cna@vuldb.com)
https://vuldb.com/?ctiid.325691(cna@vuldb.com)
https://vuldb.com/?id.325691(cna@vuldb.com)
https://vuldb.com/?submit.653994(cna@vuldb.com)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.