CVE-2026-40604
Severity CVSS v4.0:
HIGH
Type:
CWE-693
Protection Mechanism Failure
Publication date:
21/04/2026
Last modified:
24/04/2026
Description
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.6, the opfilter Endpoint Security system extension (bundle ID uk.craigbass.clearancekit.opfilter) can be suspended with SIGSTOP or kill -STOP, or killed with SIGKILL/SIGTERM, by any process running as root. While the extension is suspended, all AUTH Endpoint Security events time out and default to allow, silently disabling ClearanceKit's file-access policy enforcement for the duration of the suspension. This vulnerability is fixed in 5.0.6.
Impact
Base Score 4.0
8.20
Severity 4.0
HIGH
Base Score 3.x
4.40
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:craigjbass:clearancekit:*:*:*:*:*:*:*:* | 5.0.6 (excluding) | |
| cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



