Mattermost Desktop App allows the bypass of Transparency, Consent, and Control (TCC) via code injection
Low severity
GitHub Reviewed
Published
Mar 17, 2025
to the GitHub Advisory Database
•
Updated Mar 17, 2025
Description
Published by the National Vulnerability Database
Mar 17, 2025
Published to the GitHub Advisory Database
Mar 17, 2025
Reviewed
Mar 17, 2025
Last updated
Mar 17, 2025
Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.
References