CVE Explorer
CVE-2025-8672
MacOS version of GIMP bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions
granted by the user to the main application bundle. An attacker with local user access can
invoke this interpreter with arbitrary commands or scripts, leveraging the
application's previously granted TCC permissions to access user's files in privacy-protected folders without triggering user prompts. Accessing other resources beyond previously granted TCC permissions will promp
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","platforms":["MacOS"],"product":"GIMP","repo":"https://gitlab.gnome.org/GNOME/gimp/","vendor":"GIMP","versions":[{"lessThan":"3.1.4.2","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d4bb342a2b696abed820fff8555f0e3b0ebc4b25fb5e3bac94dcff62ed54a902 · sha256:a12bb507da08d689… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"LOCAL","baseScore":4.8,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW",…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d4bb342a2b696abed820fff8555f0e3b0ebc4b25fb5e3bac94dcff62ed54a902 · sha256:a12bb507da08d689… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-276","description":"CWE-276 Incorrect Default Permissions","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d4bb342a2b696abed820fff8555f0e3b0ebc4b25fb5e3bac94dcff62ed54a902 · sha256:a12bb507da08d689… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"tags":["third-party-advisory"],"url":"https://cert.pl/en/posts/2025/08/tcc-bypass/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d4bb342a2b696abed820fff8555f0e3b0ebc4b25fb5e3bac94dcff62ed54a902 · sha256:a12bb507da08d689… · /containers/cna/references/1
{"tags":["issue-tracking"],"url":"https://gitlab.gnome.org/GNOME/gimp/-/issues/13848"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d4bb342a2b696abed820fff8555f0e3b0ebc4b25fb5e3bac94dcff62ed54a902 · sha256:a12bb507da08d689… · /containers/cna/references/3
{"tags":["product"],"url":"https://gitlab.gnome.org/Infrastructure/gimp-macos-build"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d4bb342a2b696abed820fff8555f0e3b0ebc4b25fb5e3bac94dcff62ed54a902 · sha256:a12bb507da08d689… · /containers/cna/references/0
{"tags":["technical-description"],"url":"https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d4bb342a2b696abed820fff8555f0e3b0ebc4b25fb5e3bac94dcff62ed54a902 · sha256:a12bb507da08d689… · /containers/cna/references/2
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.