Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with world-writable file permissions on sensitive application components, allowing any local user to replace legitimate files with malicious code. When another user launches the application, the malicious code executes with that user's privileges, enabling privilege escalation and unauthorized access to sensitive data. The fix is included starting from the `2.3.7` release.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with world-writable file permissions on sensitive application components, allowing any local user to replace legitimate files with malicious code. When another user launches the application, the malicious code executes with that user's privileges, enabling privilege escalation and unauthorized access to sensitive data. The fix is included starting from the `2.3.7` release. | |
| Title | Arduino IDE for macOS has Insecure File Permissions | |
| Weaknesses | CWE-276 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-18T15:18:39.642Z
Reserved: 2025-11-10T14:07:42.923Z
Link: CVE-2025-64724
No data.
Status : Received
Published: 2025-12-18T16:15:55.623
Modified: 2025-12-18T16:15:55.623
Link: CVE-2025-64724
No data.
OpenCVE Enrichment
No data.