DaVinci Resolve on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent with standard macOS security practices, where applications should have drwxr-xr-x permissions. Incorrect permissions allow for Dylib Hijacking. Guest account, other users and applications can exploit this vulnerability for privilege escalation. This issue affects DaVinci Resolve on MacOS in versions before 19.1.3.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://cert.pl/en/posts/2025/02/CVE-2025-1413/ | third party advisory |
https://cert.pl/posts/2025/02/CVE-2025-1413/ | third party advisory |
https://apps.apple.com/pl/app/davinci-resolve/id571213070?mt=12 | product |