CVE-2025-9815

Severity CVSS v4.0:
HIGH
Type:
CWE-287 Authentication Issues
Publication date:
02/09/2025
Last modified:
04/09/2025

Description

A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function of the file PrivilegeHelper/PrivilegeHelper.swift of the component NSXPCListener. This manipulation causes missing authentication. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be exploited.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:alaneuler:batterykid:*:*:*:*:*:*:*:* 2.1 (including)
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*