iStat Menus < 7.20.5 local privilege escalation
This blog post covers a boring local privilege escalation bug in iStat Menus due to a misconfigured folder permission. I was honestly surprised this was overlooked, since there were other recently disclosed vulnerabilities, one of which was way more interesting. Read here. TL;dr Insecure world-writable folder allowing privilege escalation Affected versions < 7.20.5 with Install Helper component No profit (a reboot is required) A CVE has been requested Description In my day-to-day job I occasionally review software for security issues....