CVE-2025-4412 - CVE House
Back to Database
Status published Medium CVE-2025-4412

TCC Bypass via Dylib Loading in Viscosity.app

Vulnerability Description

On macOS systems, by utilizing a Launch Agent and loading the viscosity_openvpn process from the application bundle, it is possible to load a dynamic library with Viscosity's TCC (Transparency, Consent, and Control) identity. The acquired resource access is limited without entitlements such as access to the camera or microphone. Only user-granted permissions for file resources apply. Access to other resources beyond granted-permissions requires user interaction with a system prompt asking for permission. This issue was fixed in version 1.11.5 of Viscosity.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-4412

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Karol Mazurek - Afine Team

Affected Vendor

Affected Software

Viscosity
Vulnerable Versions:
0

Timeline

Official Publish: May 27th, 2025
Last Modified: June 6th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)