CVE-2025-65842
The Aquarius HelperTool (1.0.003) privileged XPC service on macOS contains multiple flaws that allow local privilege escalation. The service accepts XPC connections from any local process without validating the client's identity, and its authorization logic incorrectly calls AuthorizationCopyRights with a NULL reference, causing all authorization checks to succeed. The executeCommand:authorization:withReply: method then interpolates attacker-controlled input into NSTask and executes it with root privileges. A local attacker can exploit these weaknesses to run arbitrary commands as root, create persistent backdoors, or obtain a fully interactive root shell.
Published:Dec 3, 2025
Last Modified:Dec 18, 2025
EPS:Dec 3, 2025
EPSS Score:0.00015
CVSS Score:5.1
Affected Products
Vendor
Product
Action
Vendor
Acustica-audio
Product
Aquarius Helpertool
Acustica-audio
Aquarius Helpertool
Vendor
Acusticaudio
Product
Aquarius Helpertool
Acusticaudio
Aquarius Helpertool
Vendor
Apple
Product
Macos
Apple
Macos
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
