CVE-2025-65841 describes a critical vulnerability in Aquarius Desktop 3.0.069 for macOS, where user authentication credentials are stored insecurely in a local settings file using easily reversible obfuscation. This allows an attacker with local file access to trivially recover plaintext passwords, leading to complete account takeover and unauthorized access to cloud-synchronized data. Rated 6.2 MEDIUM, the vulnerability has a low attack complexity and no user interaction required, but it necessitates local access to the affected system. Currently, there is no public exploit code, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.069CPE matchmatch criteria | cpe:2.3:a:acustica-audio:aquarius:3.0.069:*:*:*:*:macos:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.