CVE-2025-10906
Severity CVSS v4.0:
HIGH
Type:
CWE-287
Authentication Issues
Publication date:
24/09/2025
Last modified:
29/04/2026
Description
A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS. This affects the function loadModuleNamed:WithReply of the file /Applications/Endurance.app/Contents/Library/LaunchServices/com.MagnetismStudios.endurance.helper of the component NSXPC Interface. Executing manipulation can lead to missing authentication. The attack needs to be launched locally. The exploit has been published and may be used.
Impact
Base Score 4.0
7.30
Severity 4.0
HIGH
Base Score 3.x
8.40
Severity 3.x
HIGH
Base Score 2.0
7.20
Severity 2.0
HIGH


