iStats contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via command injection.This issue affects iStats: 7.10.4.
Metrics
Affected Vendors & Products
References
History
Mon, 24 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Nov 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | iStats contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via command injection.This issue affects iStats: 7.10.4. | |
| Title | iStat Menus 7.10.4 - Local Privilege Escalation | |
| First Time appeared |
Bjango
Bjango istats |
|
| Weaknesses | CWE-732 CWE-77 |
|
| CPEs | cpe:2.3:a:bjango:istats:7.10.4:*:macos:*:*:*:*:* | |
| Vendors & Products |
Bjango
Bjango istats |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published: 2025-11-24T14:22:12.801Z
Updated: 2025-11-24T15:01:30.333Z
Reserved: 2025-10-17T17:02:17.363Z
Link: CVE-2025-11921
Updated: 2025-11-24T15:01:15.085Z
Status : Received
Published: 2025-11-24T15:15:45.817
Modified: 2025-11-24T15:15:45.817
Link: CVE-2025-11921
No data.