Dylib Hijacking in DaVinci Resolve
Vulnerability Description
DaVinci Resolve on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent with standard macOS security practices, where applications should have drwxr-xr-x permissions. Incorrect permissions allow for Dylib Hijacking. Guest account, other users and applications can exploit this vulnerability for privilege escalation. This issue affects DaVinci Resolve on MacOS in versions before 19.1.3.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-1413
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Karol Mazurek with AFINE
Affected Vendor
Blackmagic Design Inc
View all reports →