
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13326 is a protection mechanism failure in the Mattermost Desktop App for macOS that allows a local attacker to inherit Transparency, Consent, and Control (TCC) permissions by copying the application binary to a temporary folder. The vulnerability affects all Mattermost Desktop App versions prior to 6.0.0 when packaged for the Mac App Store, as the app fails to enable the macOS Hardened Runtime entitlement. It was published on December 17, 2025, with a CVSS v3.1 base score of 3.9 (Low) (Red Hat CVE, Mattermost Security).
The root cause is classified as CWE-693 (Protection Mechanism Failure): the Mattermost Desktop App, when distributed via the Mac App Store, does not enable the macOS Hardened Runtime, a security feature that restricts code injection, dynamic library loading, and other runtime tampering. Without Hardened Runtime enabled, the application binary can be copied to a world-writable directory (e.g., /tmp) and executed in a context that inherits the original app's TCC permissions — such as access to the microphone, camera, or contacts — without user re-authorization. Exploitation requires local access, low privileges, and user interaction, limiting the attack surface to authenticated local users on affected macOS systems (Red Hat CVE, Mattermost Security).
Successful exploitation allows a low-privileged local attacker to bypass macOS TCC security controls and inherit sensitive permissions originally granted to the Mattermost Desktop App, potentially including access to the microphone, camera, contacts, or other protected resources. Both confidentiality and integrity are impacted at a low level, while availability is unaffected. The scope is limited to the local system and does not enable remote code execution or privilege escalation beyond TCC permission inheritance (Red Hat CVE).
/Applications/Mattermost.app/Contents/MacOS/Mattermost)./tmp/ — e.g., cp /Applications/Mattermost.app/Contents/MacOS/Mattermost /tmp/Mattermost./tmp/, /var/folders/, or other temporary paths outside the standard application bundle location./Applications/Mattermost.app/ or the user's ~/Applications/ directory.log show) indicating TCC permission grants or access events attributed to a binary running from a temporary directory; tccd log entries showing permission inheritance for unexpected process paths./tmp or similar locations.Mattermost has addressed this vulnerability in Mattermost Desktop App version 6.0.0, which enables the Hardened Runtime entitlement for Mac App Store builds. Users should upgrade to version 6.0.0 or later immediately via the Mac App Store. As interim mitigations, administrators should restrict local user access on macOS systems, apply the principle of least privilege, and monitor for unauthorized binary manipulations or processes running from temporary directories (Mattermost Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."