Shirt Pocket develops SuperDuper, a macOS backup and cloning utility that handles sensitive system-level operations and disk imaging. This focused product line represents a niche vendor footprint in the landscape; current vulnerability counts, severity, and any exploitation activity are shown in the live panel alongside this summary.
The number and severity of CVEs published that impact products developed by Shirt Pocket over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-57489HIGH Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privileges to root due to the improper use of a setuid binary. | Dec 1, 2025 | 8.1 | 28 | NO | NO |
CVE-2025-69604HIGH An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with r | Jan 29, 2026 | 7.8 | 27 | NO | NO |
CVE-2025-61229HIGH An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight script with root privileges and | Dec 1, 2025 | 7.8 | 27 | NO | NO |
CVE-2025-61228HIGH An issue in Shirt Pocket SuperDuper! V.3.10 and before allows a local attacker to execute arbitrary code via the software update mechanism | Dec 1, 2025 | 7.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shirt Pocket.
Media articles that mention a CVE ID that affects a product developed by Shirt Pocket — matched by CVE ID, not by vendor name.