
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-25364 is a command injection vulnerability in the me.connectify.SMJobBlessHelper XPC service of Speedify VPN for macOS, affecting all versions up to and including v15.0.0. The flaw allows local attackers to execute arbitrary commands with root-level privileges without requiring any user interaction or prior privileges. It was published on December 23, 2025, and assigned a CVSS v3.1 base score of 8.4 (High) by CISA-ADP (Speedify Advisory, RedHat CVE).
The vulnerability is classified as CWE-77 (Improper Neutralization of Special Elements used in a Command), meaning the me.connectify.SMJobBlessHelper XPC service fails to properly sanitize user-supplied input before passing it to system-level commands. The SMJobBlessHelper is a privileged helper tool installed via macOS's SMJobBless API, which runs with root privileges to perform administrative tasks on behalf of the main application. An attacker with local access can send a crafted message to this XPC service, injecting shell metacharacters or command delimiters that cause the helper to execute attacker-controlled commands as root. A technical write-up was published by SecureLayer7 detailing the privilege escalation mechanics (SecureLayer7 Blog).
Successful exploitation grants an attacker root-level code execution on the affected macOS system, resulting in complete compromise of confidentiality, integrity, and availability. An attacker can read, modify, or delete any file on the system, install persistent malware or backdoors, disable security controls, and potentially pivot to other systems on the same network. The scope is limited to the local machine, but the severity is maximized by the unconditional root privilege escalation (Feedly, GBHackers).
As of the time of reporting, no public proof-of-concept exploit code has been confirmed, and there is no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.048%, indicating a low current probability of exploitation in the near term. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been made (Feedly, SecureLayer7 Blog).
me.connectify.SMJobBlessHelper privileged helper in /Library/PrivilegedHelperTools/.me.connectify.SMJobBlessHelper XPC service, which runs as root and listens for inter-process communication from the Speedify VPN application.;, &&, |, or backticks) within parameters that are passed unsanitized to a system command.me.connectify.SMJobBlessHelper (e.g., /bin/bash, /bin/sh, curl, python, osascript) visible in process listings or audit logs.me.connectify.SMJobBlessHelper; sudo or launchd log entries reflecting unexpected root-level command execution./Library/LaunchDaemons/, /etc/, /usr/local/bin/) by the Speedify helper process; unexpected modifications to system files or cron jobs.Speedify has released a patch addressing this vulnerability; users should update Speedify VPN to a version later than v15.0.0 immediately (Speedify Advisory). As a temporary workaround, administrators can restrict local user access to the affected macOS systems and monitor for unauthorized command execution. Implementing strong access controls and network segmentation can reduce the potential impact if exploitation occurs prior to patching.
The vulnerability received notable coverage across security news outlets including GBHackers, CyberSecurityNews, and ITSecurityNews following its public disclosure in April 2025. The r/netsec subreddit and security-focused Mastodon and Bluesky accounts shared the advisory, generating community discussion about the risks of privileged VPN helper processes on macOS. SecureLayer7 published a dedicated technical blog post analyzing the privilege escalation mechanism, which was widely referenced (SecureLayer7 Blog, GBHackers, Reddit netsec).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."