CVE-2025-9474
Severity CVSS v4.0:
LOW
Type:
Unavailable / Other
Publication date:
26/08/2025
Last modified:
26/08/2025
Description
A vulnerability was detected in Mihomo Party up to 1.8.1 on macOS. Affected is the function enableSysProxy of the file src/main/sys/sysproxy.ts of the component Socket Handler. The manipulation results in creation of temporary file with insecure permissions. The attack requires a local approach. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit is now public and may be used.
Impact
Base Score 4.0
2.00
Severity 4.0
LOW
Base Score 3.x
4.50
Severity 3.x
MEDIUM
Base Score 2.0
3.50
Severity 2.0
LOW