Security Advisory

CVE-2026-12374

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-01 14:07:28
Last updated 2026-07-01 15:07:24
Assigner Cato
CVSS score 6.4
State PUBLISHED

Description

Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC service in Cato Client before v.5.13.1 on macOS allows a local authenticated attacker to escalate privileges to root via a self-signed certificate that bypasses the XPC caller verification and a symlink swap during package installation.