CVE-2025-1413

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
28/02/2025
Last modified:
26/03/2025

Description

DaVinci Resolve on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent with standard macOS security practices, where applications should have drwxr-xr-x permissions. Incorrect permissions allow for Dylib Hijacking. Guest account, other users and applications can exploit this vulnerability for privilege escalation. This issue affects DaVinci Resolve on MacOS in versions before 19.1.3.