Vulnerability Description
AirVPN Eddie on MacOS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.This issue affects Eddie: 2.24.6.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Airvpn | Eddie | 2.24.6 |
Related Weaknesses (CWE)
References
- https://airvpn.org/forums/topic/79305-eddie-desktop-edition-225-beta-released/Issue TrackingRelease Notes
- https://eddie.website/Product
- https://fluidattacks.com/advisories/blink182ExploitThird Party Advisory
- https://github.com/AirVPN/EddieProduct
FAQ
What is CVE-2025-14979?
CVE-2025-14979 is a vulnerability with a CVSS score of 7.8 (HIGH). AirVPN Eddie on MacOS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.This issue affects Eddie: 2.24.6.
How severe is CVE-2025-14979?
CVE-2025-14979 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-14979?
Check the references section above for vendor advisories and patch information. Affected products include: Airvpn Eddie.