CVE-2025-10906: Magnetism Studios Endurance
High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.
A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS. This affects the function loadModuleNamed:WithReply of the file /Applications/Endurance.app/Contents/Library/LaunchServices/com.MagnetismStudios.endurance.helper of the component NSXPC Interface. Executing manipulation can lead to missing authentication. The attack needs to be launched locally. The exploit has been published and may be used.
Affected products
- Magnetism Studios Endurance: version 3.0 only; version 3.1 only; version 3.2 only; version 3.3.0 only
Published 2025-09-24. Last modified 2026-09-26.