Arduino IDE for macOS has TCC Bypass via Dynamic Library Injection
Vulnerability Description
Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS was configured with overly permissive security entitlements that could bypass macOS Hardened Runtime protections. This configuration allows attackers to inject malicious dynamic libraries into the application process, gaining access to all TCC (Transparency, Consent, and Control) permissions granted to the application. The fix is included starting from the `2.3.7 ` release.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-64723
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/arduino/arduino-ide/security/advisories/GHSA-vf5j-xhwq-8vqj
- https://github.com/arduino/arduino-ide/pull/2805
- https://github.com/arduino/arduino-ide/commit/1fa0fd31c8d6b62f19332e33713a8c5b0f4ed6f9
- https://github.com/arduino/arduino-ide/releases/tag/2.3.7
- https://support.arduino.cc/hc/en-us/articles/24329484618652-ASEC-25-004-Arduino-IDE-v2-3-7-Resolves-Multiple-Vulnerabilities
More from arduino
View All →Affected Vendor
arduino
View all reports →