Macpaw's vulnerability profile centers on CleanMyMac X, a system-optimization utility for macOS with a notable presence in the consumer cleanup-software landscape. The recurring weakness classes—improper input validation and incomplete cleanup—reflect the product's broad interaction with the file system and system resources, areas where boundary-handling and state-management lapses pose risk to local system integrity. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Macpaw over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5011MEDIUM An exploitable privilege escalation vulnerability exists in the helper service CleanMyMac X, version 4.20, due to improper updating. The application failed to remove the vulnerable | Mar 21, 2019 | 5.5 | 20 | NO | NO |
CVE-2018-4047MEDIUM An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access coul | Jan 10, 2019 | 5.5 | 20 | NO | NO |
CVE-2018-4046MEDIUM An exploitable denial-of-service vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. A user with local access can use this | Jan 10, 2019 | 5.5 | 20 | NO | NO |
CVE-2018-4045MEDIUM An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access coul | Jan 10, 2019 | 5.5 | 20 | NO | NO |
CVE-2018-4044MEDIUM An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access coul | Jan 10, 2019 | 5.5 | 20 | NO | NO |
CVE-2018-4043MEDIUM An exploitable privilege escalation vulnerability exists in the Clean My Mac X, version 4.04, helper service due to improper input validation. A user with local access can use this | Jan 10, 2019 | 5.5 | 20 | NO | NO |
CVE-2018-4042MEDIUM An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access coul | Jan 10, 2019 | 5.5 | 20 | NO | NO |
CVE-2018-4041MEDIUM An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access coul | Jan 10, 2019 | 5.5 | 20 | NO | NO |
CVE-2018-4037MEDIUM The CleanMyMac X software contains an exploitable privilege escalation vulnerability due to improper input validation. An attacker with local access can use this vulnerability to m | Jan 10, 2019 | 5.5 | 20 | NO | NO |
CVE-2018-4036MEDIUM The CleanMyMac X software contains an exploitable privilege escalation vulnerability due to improper input validation. An attacker with local access could use this vulnerability to | Jan 10, 2019 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Macpaw.
Media articles that mention a CVE ID that affects a product developed by Macpaw — matched by CVE ID, not by vendor name.