一、 漏洞 CVE-2025-1078 基础信息
漏洞标题
AppHouseKitchen AlDente Charge Limiter XPC 服务 com.apphousekitchen.aldente-pro.helper shouldAcceptNewConnection 认证不当漏洞
来源:AIGC 神龙大模型
漏洞描述信息
在AppHouseKitchen AlDente Charge Limiter 1.29及之前版本中发现了一个漏洞,该漏洞影响了macOS系统,并被分类为严重。此漏洞影响组件XPC Service中的文件com.apphousekitchen.aldente-pro.helper的shouldAcceptNewConnection函数。该漏洞可能导致授权不当。攻击者可以在本地主机上发起攻击。该漏洞的利用细节已被公开并可能被利用。升级到1.30版本可以解决此问题。建议升级受影响的组件。厂商在漏洞披露早期被联系,并且处理得非常专业。
来源:AIGC 神龙大模型
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
来源:AIGC 神龙大模型
漏洞类别
授权机制不正确
来源:AIGC 神龙大模型
漏洞标题
AppHouseKitchen AlDente Charge Limiter XPC Service com.apphousekitchen.aldente-pro.helper shouldAcceptNewConnection improper authorization
来源:美国国家漏洞数据库 NVD
漏洞描述信息
A vulnerability has been found in AppHouseKitchen AlDente Charge Limiter up to 1.29 on macOS and classified as critical. This vulnerability affects the function shouldAcceptNewConnection of the file com.apphousekitchen.aldente-pro.helper of the component XPC Service. The manipulation leads to improper authorization. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. Upgrading to version 1.30 is able to address this issue. It is recommended to upgrade the affected component. The vendor was contacted early about this disclosure and acted very professional.
来源:美国国家漏洞数据库 NVD
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
来源:美国国家漏洞数据库 NVD
漏洞类别
授权机制不恰当
来源:美国国家漏洞数据库 NVD
二、漏洞 CVE-2025-1078 的公开POC
# POC 描述 源链接 神龙链接
三、漏洞 CVE-2025-1078 的情报信息
  • 标题: AlDente-Charge-Limiter... | Winslow Blog -- 🔗来源链接

    标签: exploit

  • 标题: Login required -- 🔗来源链接

    标签: signature permissions-required

  • 标题: Submit #492529: AppHouseKitchen AlDente - Charge Limiter < 1.30 Privilege Escalation -- 🔗来源链接

    标签: third-party-advisory

  • 标题: CVE-2025-1078 AppHouseKitchen AlDente Charge Limiter XPC Service com.apphousekitchen.aldente-pro.helper shouldAcceptNewConnection improper authorization -- 🔗来源链接

    标签: vdb-entry technical-description

  • https://nvd.nist.gov/vuln/detail/CVE-2025-1078