ws.stash.app.mac.daemon.helper Privilege Escalation Vulnerability Allowing Unauthorized Changes to Network Preferences

Vulnerability

A vulnerability in the ws.stash.app.mac.daemon.helper tool has been identified, stemming from a misapplication of macOS's authorization model. The helper improperly validates the client's authorization reference, instead using its own privileged context (root) to authorize itself. This flaw allows unprivileged clients to perform privileged operations via XPC, such as making unauthorized changes to system-wide network preferences, including SOCKS, HTTP, and HTTPS proxy settings. Additionally, the lack of proper code-signing checks enables arbitrary processes to exploit this vulnerability, potentially leading to man-in-the-middle attacks by redirecting traffic.

Impact

Exploitation of this vulnerability could allow unprivileged clients to invoke privileged operations, unauthorized changes to system-wide network preferences, and facilitate man-in-the-middle attacks through traffic redirection.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.3
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.