
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-10751 is a local privilege escalation vulnerability in MacForge, an open-source plugin manager for macOS developed by MacEnhance. The vulnerability stems from an insecure XPC service that allows local, unprivileged users to escalate their privileges to root without any user interaction. It affects MacForge version 1.2.0 Beta 1 exclusively. The CVE was published on October 4, 2025, and was assigned by Fluid Attacks. It carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.5 (High) (Red Hat CVE, Fluid Attacks Advisory).
The root cause is classified as CWE-732 (Incorrect Permission Assignment for Critical Resource), where MacForge's XPC service is configured with insufficient access controls, allowing any local user process to communicate with and abuse the privileged service (Red Hat CVE). XPC is Apple's inter-process communication framework; when an XPC service runs with elevated privileges but does not properly validate or restrict which callers can invoke its methods, low-privileged local users can send crafted XPC messages to trigger privileged operations. Exploitation requires only low-privileged local access, no user interaction, and has low attack complexity, making it straightforward to exploit once local access is obtained (Fluid Attacks Advisory). A proof-of-concept is publicly available via Fluid Attacks' advisory.
Successful exploitation grants a local, unprivileged attacker full root-level control of the affected macOS system. This enables complete system compromise, including unauthorized access to sensitive data, modification of system configurations, installation of malware or backdoors, and creation of additional administrative accounts. Given that MacForge itself requires System Integrity Protection (SIP) to be partially or fully disabled for its plugin injection functionality, systems running MacForge may already have reduced macOS security posture, amplifying the risk (Fluid Attacks Advisory, MacForge GitHub).
A proof-of-concept exploit is publicly available via Fluid Attacks' advisory page, published around December 22, 2025 (Fluid Attacks Advisory). There is no confirmed evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.012% (0.000120), indicating a currently low probability of widespread exploitation. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. However, the public availability of a PoC and the low exploitation complexity (local access with low privileges, no user interaction required) elevate the practical risk for affected systems.
launchctl list or by inspecting MacForge's application bundle for registered XPC service definitions (e.g., within Contents/XPCServices/).log show) showing unexpected XPC connections to MacForge's privileged helper service from unprivileged user processes; sudo or auth log entries showing privilege escalation without corresponding user authentication./etc/sudoers, /Library/LaunchDaemons/, or other root-owned system paths; new files or scripts created in privileged directories by non-root users.No vendor patch has been confirmed as available for MacForge 1.2.0 Beta 1 at the time of disclosure. Users should consider uninstalling or disabling MacForge until a patched version is released (Fluid Attacks Advisory). As an interim measure, restrict local user access on systems running MacForge, enforce least-privilege principles, and monitor for unauthorized privilege escalation attempts. Organizations should also note that MacForge requires SIP to be partially disabled, which independently weakens macOS security; re-enabling SIP where possible is advisable. Monitor the MacForge GitHub repository for patch releases.
The vulnerability was discovered and disclosed by Fluid Attacks, who published a dedicated advisory. Social media activity was limited, with brief mentions on Bluesky and Mastodon/Infosec.exchange from security monitoring accounts shortly after disclosure (Fluid Attacks Advisory). No significant vendor statement from MacEnhance has been publicly identified. The vulnerability received standard coverage from automated vulnerability tracking services (VulnDB, CVEFeed, CIRCL) but has not attracted major media attention, likely due to the niche user base of MacForge.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."