CVE-2021-32692 is a critical vulnerability affecting Activity Watch versions prior to 0.11.0 on macOS, allowing arbitrary command execution. An attacker can exploit this by tricking a user into visiting a malicious website with a crafted page title, leading to complete compromise of the system. With a CVSS score of 9.6, this vulnerability is easily exploitable over a network with low complexity and user interaction, resulting in high impact to confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, the high FAUCET Risk Score indicates its significant potential danger.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.11.0CPE matchmatch criteria | cpe:2.3:a:activitywatch:activitywatch:*:*:*:*:*:*:*:* | ||
>= 0.11.0, < 0.11.0CPE match | cpe:2.3:a:activitywatch:activitywatch:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.