SB20260408102 - Privilege Dropping / Lowering Errors in nix



SB20260408102 - Privilege Dropping / Lowering Errors in nix

Published: April 8, 2026

Security Bulletin ID SB20260408102
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Privilege Dropping / Lowering Errors (CVE-ID: CVE-2025-53819)

The vulnerability allows a local user to execute builds with elevated privileges.

The vulnerability exists due to privilege dropping / lowering errors in the build user privilege dropping mechanism when executing builds on macOS. A local user can trigger a build to execute it as root to execute builds with elevated privileges.

On affected macOS systems, builds were executed as root instead of the intended build users.


Remediation

Install update from vendor's website.