CVE-2025-1398
CVSS 3.1 Score 3.3 of 10 (low)
Details
Published Mar 17, 2025
Updated: Mar 31, 2025
CWE ID 426
Summary
CVE-2025-1398 is a vulnerability affecting Mattermost Desktop App versions prior to 5.10.1. The issue arises from theapps' explicit declaration of unnecessary macOS entitlements, which enables an attacker with remote access to bypass the Transparency, Consent, and Control (TCC) security mechanism via code injection. This vulnerability can potentially lead to unauthorized access or manipulation of user data, posing a significant risk. Users are strongly encouraged to update their Mattermost Desktop App to the latest version to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Mattermost, Inc.