CVE-2025-9474

A vulnerability was detected in Mihomo Party up to 1.8.1 on macOS. Affected is the function enableSysProxy of the file src/main/sys/sysproxy.ts of the component Socket Handler. The manipulation results in creation of temporary file with insecure permissions. The attack requires a local approach. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit is now public and may be used.
Configurations

No configuration.

History

No history.

Information

Published : 2025-08-26 05:15

Updated : 2025-08-26 13:41


NVD link : CVE-2025-9474

Mitre link : CVE-2025-9474

CVE.ORG link : CVE-2025-9474


JSON object : View

Products Affected

No product.

CWE
CWE-377

Insecure Temporary File

CWE-378

Creation of Temporary File With Insecure Permissions