CVE Feed

    Dashboard / CVE / CVE-2025-14714

    CVE-2025-14714

    An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle By executing the bundled interpreter directly the attacker's scripts run with the application's TCC privileges In fixed versions parent-constraints are used to allow only the main application to launch interpreter with those permissions This issue affects LibreOffice on macOS: from 25.2 before < 25.2.4.

    Published:Dec 15, 2025
    Last Modified:Feb 18, 2026
    EPS:Dec 15, 2025
    EPSS Score:0.00018
    CVSS Score:6.5

    Affected Products

    Vendor
    Apple
    Product
    Macos
    Vendor
    Libreoffice
    Product
    Libreoffice
    Vendor
    The Document Foundation
    Product
    Libreoffice

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High