iStats contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via command injection.This issue affects iStats: 7.10.4.
History

Mon, 24 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Nov 2025 14:45:00 +0000

Type Values Removed Values Added
Description iStats contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via command injection.This issue affects iStats: 7.10.4.
Title iStat Menus 7.10.4 - Local Privilege Escalation
First Time appeared Bjango
Bjango istats
Weaknesses CWE-732
CWE-77
CPEs cpe:2.3:a:bjango:istats:7.10.4:*:macos:*:*:*:*:*
Vendors & Products Bjango
Bjango istats
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published: 2025-11-24T14:22:12.801Z

Updated: 2025-11-24T15:01:30.333Z

Reserved: 2025-10-17T17:02:17.363Z

Link: CVE-2025-11921

cve-icon Vulnrichment

Updated: 2025-11-24T15:01:15.085Z

cve-icon NVD

Status : Received

Published: 2025-11-24T15:15:45.817

Modified: 2025-11-24T15:15:45.817

Link: CVE-2025-11921

cve-icon Redhat

No data.