CVE Explorer
CVE-2026-33632
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4.2.4, two file operation event types — ES_EVENT_TYPE_AUTH_EXCHANGEDATA and ES_EVENT_TYPE_AUTH_CLONE — were not intercepted by ClearanceKit's opfilter system extension, allowing local processes to bypass file access policies. Commit 6181c4a patches the vulnerability by subscribing to both event types and routing them through the existing policy evaluator. Users must upgrade to v4
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"clearancekit","vendor":"craigjbass","versions":[{"status":"affected","version":"< 4.2.4"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:58bc02e0d6ded57f043b9b2c81780c4b2d530044ca093c5ee10a0c1c0d5d681c · sha256:32633837786420c0… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"LOCAL","baseScore":8.4,"baseSeverity":"HIGH","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:L/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:58bc02e0d6ded57f043b9b2c81780c4b2d530044ca093c5ee10a0c1c0d5d681c · sha256:32633837786420c0… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-862","description":"CWE-862: Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:58bc02e0d6ded57f043b9b2c81780c4b2d530044ca093c5ee10a0c1c0d5d681c · sha256:32633837786420c0… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/craigjbass/clearancekit/commit/6181c4a22eccbeca973c77f4bd023eb795c13786","tags":["x_refsource_MISC"],"url":"https://github.com/craigjbass/clearancekit/commit/6181c4a22eccbeca973c77f4bd023eb795c13786"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:58bc02e0d6ded57f043b9b2c81780c4b2d530044ca093c5ee10a0c1c0d5d681c · sha256:32633837786420c0… · /containers/cna/references/1
{"name":"https://github.com/craigjbass/clearancekit/security/advisories/GHSA-wpxj-vhfp-hhvm","tags":["x_refsource_CONFIRM"],"url":"https://github.com/craigjbass/clearancekit/security/advisories/GHSA-wpxj-vhfp-hhvm"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:58bc02e0d6ded57f043b9b2c81780c4b2d530044ca093c5ee10a0c1c0d5d681c · sha256:32633837786420c0… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.