CVE-2025-61229: Shirt-Pocket Superduper!

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight script with root privileges and Full Disk Access, thus bypassing macOS privacy controls.

Affected products

Published 2025-12-01. Last modified 2026-07-05.