CVE-2020-13095: Obdev Little Snitch

High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.

Little Snitch version 4.5.1 and older changed ownership of a directory path controlled by the user. This allowed the user to escalate to root by linking the path to a directory containing code executed by root.

Affected products

  • Obdev Little Snitch: up to and including 4.5.1

Published 2020-06-30. Last modified 2026-06-17.