Two high-severity vulnerabilities in ClearanceKit on macOS allowed locally running processes to bypass the product’s opfilter file access enforcement and evade per-process authorization policies. CVE-2026-33631 affected the 4.1 branch and earlier because the Endpoint Security extension enforced policy only for ES_EVENT_TYPE_AUTH_OPEN and missed seven other file operation event types, while CVE-2026-33632 affected versions before 4.2.4 because ES_EVENT_TYPE_AUTH_EXCHANGEDATA and ES_EVENT_TYPE_AUTH_CLONE were not intercepted. Both flaws were classified as CWE-862 and could expose protected files to unauthorized local access or modification.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
A vulnerability later assigned CVE-2026-40604 was fixed in ClearanceKit 5.0.6 after it was found that any root process could suspend or terminate the opfilter Endpoint Security system extension with signals such as SIGSTOP, SIGKILL, or SIGTERM. When opfilter was interrupted, AUTH events timed out and defaulted to allow, silently disabling file-access policy enforcement.
Two high-severity local policy-bypass vulnerabilities in ClearanceKit on macOS were publicly disclosed: CVE-2026-33631 affecting the 4.1 branch and earlier, and CVE-2026-33632 affecting versions before 4.2.4. Both issues allowed local processes to circumvent per-process file access controls because opfilter failed to inspect certain Endpoint Security file operation events.
A separate flaw later assigned CVE-2026-33632 was patched in commit 6181c4a and released in ClearanceKit v4.2.4 after opfilter was found not to intercept AUTH_EXCHANGEDATA and AUTH_CLONE events. The update subscribed to both event types and sent them through the existing policy evaluator; users were advised to upgrade and reactivate the system extension.
A flaw later assigned CVE-2026-33631 was fixed in commit a3d1733 after developers found ClearanceKit's opfilter enforced file access policy only for AUTH_OPEN and missed seven other file operation event types. The fix added subscriptions for the missing events, routed them through the existing policy evaluator, and preserved XProtect change detection behavior for rename and unlink events.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.