CVE-2025-5963: The Postbox's configuration on macOS, specifically the presence of entitlements: "com.apple.security.cs.allow-dyld-envir
infovulnerability
security
Summary
A vulnerability in Postbox on macOS (CVE-2025-5963) allows local attackers to inject malicious code through environment variables like DYLD_INSERT_LIBRARIES, exploiting security settings that disable library validation. The injected code can bypass TCC (Transparency, Consent, and Control, which is macOS's permission system) but is limited to access that the user has already granted to the application. Since Postbox is no longer maintained and the acquiring company did not cooperate with security researchers, no patch or update is available.
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.0%
Classification
Attack SophisticationModerate
Taxonomy References
CWE (Weakness Type)
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-5963
First tracked: February 15, 2026 at 08:52 PM
Classified by LLM (prompt v3) · confidence: 95%