CVE-2026-33631Disclosure(craigjbass / clearancekit)

LOWCVSS 8.7 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch craigjbass clearancekit systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. In versions on the 4.1 branch and earlier, the opfilter Endpoint Security system extension enforced file access policy exclusively by intercepting ES_EVENT_TYPE_AUTH_OPEN events. Seven additional file operation event types were not intercepted, allowing any locally running process to bypass the configured FAA policy without triggering a denial. Commit a3d1733 adds subscriptions for all seven event types and routes them through the existing FAA policy evaluator. AUTH_RENAME and AUTH_UNLINK additionally preserve XProtect change detection: events on the XProtect path are allowed and trigger the existing onXProtectChanged callback rather than being evaluated against user policy. All versions on the 4.2 branch contain the fix. No known workarounds are available.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • clearancekit

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
clearancekit

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-26: 3Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-26: 303-26
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-33631 ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. In versions on the 4.1 branch and earlier, the opfilter Endpoint … https://www.cve.org/CVERecord?id=CVE-2026-33631

    Post summary

    CVE‑2026‑33631 describes ClearanceKit’s interception of file‑system access events on macOS, but no PoC, exploit, patch, or active exploitation details are included.

    00010128
    56.9K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33631: HIGH] ClearanceKit enhances macOS security by intercepting and enforcing file-system access. A recent fix on the 4.2 branch addresses vulnerabilities allowing process bypass of access policies.#cve,CVE-2026-33631,#cybersecurity https://cvefind.com/CVE-2026-33631

    Post summary

    CVE‑2026‑33631 is a high‑severity macOS filesystem access bypass vulnerability that has been addressed by a recent patch in ClearanceKit’s 4.2 branch, with no evidence of PoC, exploitation, or false positives.

    0000034
    617 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-33631 - High ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. In versions on the 4.1 branch and earlier, the opfilter Endpoint Security system extension... https://www.thehackerwire.com/vulnerability/CVE-2026-33631/ https://t.co/j2ynBlSkMY

    Post summary

    The post announces CVE‑2026‑33631, noting how ClearanceKit’s opfilter Endpoint Security extension fails to enforce file‑system access controls on older macOS versions, but offers no PoC, exploit code, or patch details.

    0000030
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcraigjbassclearancekit---

Explore more