CVE-2025-5199: Canonical Multipass
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker to escalate privileges by modifying files executed with administrative privileges by a Launch Daemon during system startup.
Affected products
- Canonical Multipass: before 1.16.0 (fixed in 1.16.0)
Published 2025-07-12. Last modified 2026-06-17.