Mattermost Desktop App
cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*
- <= 5.10.0
A vulnerability exists in the Mattermost Desktop App for macOS, specifically in versions through 5.10.0. The issue arises from the app explicitly declaring unnecessary macOS entitlements, which can be exploited by an attacker with remote access to inject code. This code injection allows the attacker to bypass Transparency, Consent, and Control (TCC) restrictions.
Exploitation of this vulnerability could lead to unauthorized code execution on the user's machine, allowing the attacker to bypass macOS privacy controls.
Users are advised to update to the latest version of the Mattermost Desktop App. The latest version can be downloaded from the Mattermost website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.