๐Ÿ” CVE Alert

CVE-2026-33631

HIGH 8.7

ClearanceKit: opfilter policy bypass via non-open file operations

CVSS Score
8.7
EPSS Score
0.0%
EPSS Percentile
2th

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. In versions on the 4.1 branch and earlier, the opfilter Endpoint Security system extension enforced file access policy exclusively by intercepting ES_EVENT_TYPE_AUTH_OPEN events. Seven additional file operation event types were not intercepted, allowing any locally running process to bypass the configured FAA policy without triggering a denial. Commit a3d1733 adds subscriptions for all seven event types and routes them through the existing FAA policy evaluator. AUTH_RENAME and AUTH_UNLINK additionally preserve XProtect change detection: events on the XProtect path are allowed and trigger the existing onXProtectChanged callback rather than being evaluated against user policy. All versions on the 4.2 branch contain the fix. No known workarounds are available.

CWE CWE-862
Vendor craigjbass
Product clearancekit
Published Mar 26, 2026
Last Updated Mar 30, 2026
Stay Ahead of the Next One

Get instant alerts for craigjbass clearancekit

Be the first to know when new high vulnerabilities affecting craigjbass clearancekit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
Low

Affected Versions

craigjbass / clearancekit
< 4.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/craigjbass/clearancekit/security/advisories/GHSA-25f8-8cj2-m887 github.com: https://github.com/craigjbass/clearancekit/commit/a3d1733d2691a0d40209c48b01bf9291bf645207