CVE-2025-61229: Shirt-Pocket Superduper!
High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.
An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight script with root privileges and Full Disk Access, thus bypassing macOS privacy controls.
Affected products
- Shirt-Pocket Superduper!: up to and including 3.10
Published 2025-12-01. Last modified 2026-07-05.