This issue was fixed in version 1.11.5 of Viscosity.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-17060 | On macOS systems, by utilizing a Launch Agent and loading the viscosity_openvpn process from the application bundle, it is possible to load a dynamic library with Viscosity's TCC (Transparency, Consent, and Control) identity. The acquired resource access is limited without entitlements such as access to the camera or microphone. Only user-granted permissions for file resources apply. Access to other resources beyond granted-permissions requires user interaction with a system prompt asking for permission. This issue was fixed in version 1.11.5 of Viscosity. |
Tue, 27 May 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 27 May 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On macOS systems, by utilizing a Launch Agent and loading the viscosity_openvpn process from the application bundle, it is possible to load a dynamic library with Viscosity's TCC (Transparency, Consent, and Control) identity. The acquired resource access is limited without entitlements such as access to the camera or microphone. Only user-granted permissions for file resources apply. Access to other resources beyond granted-permissions requires user interaction with a system prompt asking for permission. This issue was fixed in version 1.11.5 of Viscosity. | |
| Title | TCC Bypass via Dylib Loading in Viscosity.app | |
| Weaknesses | CWE-276 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-06-06T07:16:17.650Z
Reserved: 2025-05-07T10:11:05.905Z
Link: CVE-2025-4412
Updated: 2025-05-27T13:06:27.492Z
Status : Deferred
Published: 2025-05-27T10:15:19.383
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-4412
No data.
OpenCVE Enrichment
Updated: 2025-06-24T09:44:16Z
EUVD