CVE-2025-10906

A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS. This affects the function loadModuleNamed:WithReply of the file /Applications/Endurance.app/Contents/Library/LaunchServices/com.MagnetismStudios.endurance.helper of the component NSXPC Interface. Executing manipulation can lead to missing authentication. The attack needs to be launched locally. The exploit has been published and may be used.
Configurations

No configuration.

History

24 Sep 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-24 13:15

Updated : 2025-09-24 18:11


NVD link : CVE-2025-10906

Mitre link : CVE-2025-10906

CVE.ORG link : CVE-2025-10906


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication

CWE-306

Missing Authentication for Critical Function