CactusVPN through 6.0 for macOS suffers from a root privilege escalation vulnerability in its privileged helper tool. The privileged helper tool implements an XPC interface, which allows arbitrary applications to execute system commands as root.
Link | Tags |
---|---|
https://github.com/VerSprite/research/blob/master/advisories/VS-2018-007.md | third party advisory |