Description

FrostWire 6.14.0-build-326 for macOS contains permissive entitlements (allow-dyld-environment-variables, disable-library-validation) that allow unprivileged local attackers to inject code into the FrostWire process via the DYLD_INSERT_LIBRARIES environment variable. This allows escalated privileges to arbitrary TCC-approved directories.

INFO

Published Date :

2025-10-02T00:00:00.000Z

Last Modified :

2025-10-02T19:25:13.410Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-57443 vulnerability.

Vendors Products
Apple
  • Macos
Frostwire
  • Frostwire
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-57443.

CVSS Vulnerability Scoring System