Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with world-writable file permissions on sensitive application components, allowing any local user to replace legitimate files with malicious code. When another user launches the application, the malicious code executes with that user's privileges, enabling privilege escalation and unauthorized access to sensitive data. The fix is included starting from the `2.3.7` release.
Metrics
Affected Vendors & Products
References
History
Fri, 19 Dec 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple macos Arduino Arduino arduino |
|
| Vendors & Products |
Apple
Apple macos Arduino Arduino arduino |
Thu, 18 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with world-writable file permissions on sensitive application components, allowing any local user to replace legitimate files with malicious code. When another user launches the application, the malicious code executes with that user's privileges, enabling privilege escalation and unauthorized access to sensitive data. The fix is included starting from the `2.3.7` release. | |
| Title | Arduino IDE for macOS has Insecure File Permissions | |
| Weaknesses | CWE-276 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-18T19:06:40.437Z
Reserved: 2025-11-10T14:07:42.923Z
Link: CVE-2025-64724
Updated: 2025-12-18T18:51:08.473Z
Status : Awaiting Analysis
Published: 2025-12-18T16:15:55.623
Modified: 2025-12-19T18:00:18.330
Link: CVE-2025-64724
No data.
OpenCVE Enrichment
Updated: 2025-12-19T09:16:00Z