What the vulnerability does

01Description

Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool. The privileged helper tool implements an XPC interface which is available to any process and allows directory listings and copying files as root.

Key dates

02Disclosure timeline

August 23, 2019 CVE published
August 4, 2024 Record updated