CVE-2025-55076 - Plugin Alliance Installation Manager XPC Command Injection Vulnerability

CVE-2025-55076 - Plugin Alliance Installation Manager XPC Command Injection Vulnerability

CVE ID : CVE-2025-55076 Published : Dec. 3, 2025, 5:15 p.m. | 1 hour, 14 minutes ago Description : A local privilege escalation vulnerability exists in the InstallationHelper service included with Plugin Alliance Installation Manager v1.4.0 for macOS. The service accepts unauthenticated XPC connections and executes input via system(), which may allow a local user to execute arbitrary commands with root privileges. Severity: 6.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Dec. 3, 2025
Attack Vector: local
Impact: privilege escalation

Source: Telegram CVE Monitor