Pearcleaner's unauthenticated access to privileged XPC helper allows root command execution
Published Aug 1, 2025
7.3
HIGHCVSS 3.1
EPSS 0.18%
Description
Pearcleaner is a free, source-available and fair-code licensed mac app cleaner. The PearcleanerHelper is a privileged helper tool bundled with the Pearcleaner application. It is registered and activated only after the user approves a system prompt to allow privileged operations. Upon approval, the helper is configured as a LaunchDaemon and runs with root privileges. In versions 4.4.0 through 4.5.1, the helper registers an XPC service (com.alienator88.Pearcleaner.PearcleanerHelper) and accepts unauthenticated connections from any local process. It exposes a method that executes arbitrary shell commands. This allows any local unprivileged user to escalate privileges to root once the helper is approved and active. This issue is fixed in version 4.5.2.
Affected products
-
Affected
- ≥ 4.4.0, < 4.5.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Alienator88 | Pearcleaner | unknown | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-23383 Advisory
- https://github.com/alienator88/Pearcleaner/commit/69afadfa95791cb998118ca35c227007b230b984 x_refsource_MISC
- https://github.com/alienator88/Pearcleaner/issues/278 x_refsource_MISC
- https://github.com/alienator88/Pearcleaner/releases/tag/4.5.2 x_refsource_MISC
- https://github.com/alienator88/Pearcleaner/security/advisories/GHSA-gr2j-65fh-8pvc x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-23383 | Advisory | |
| https://github.com/alienator88/Pearcleaner/commit/69afadfa95791cb998118ca35c227007b230b984 | x_refsource_MISC | |
| https://github.com/alienator88/Pearcleaner/issues/278 | x_refsource_MISC | |
| https://github.com/alienator88/Pearcleaner/releases/tag/4.5.2 | x_refsource_MISC | |
| https://github.com/alienator88/Pearcleaner/security/advisories/GHSA-gr2j-65fh-8pvc | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data