An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle By executing the bundled interpreter directly the attacker's scripts run with the application's TCC privileges In fixed versions parent-constraints are used to allow only the main application to launch interpreter with those permissions This issue affects LibreOffice on macOS: from 25.2 before < 25.2.4.
History

Mon, 15 Dec 2025 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
The Document Foundation
The Document Foundation libreoffice
Vendors & Products Apple
Apple macos
The Document Foundation
The Document Foundation libreoffice
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 15 Dec 2025 11:00:00 +0000

Type Values Removed Values Added
Description An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle By executing the bundled interpreter directly the attacker's scripts run with the application's TCC privileges In fixed versions parent-constraints are used to allow only the main application to launch interpreter with those permissions This issue affects LibreOffice on macOS: from 25.2 before < 25.2.4.
Title TCC Bypass via Inherited Permissions in Bundled Interpreter
Weaknesses CWE-288
References
Metrics cvssV4_0

{'score': 0.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Document Fdn.

Published:

Updated: 2025-12-15T13:13:17.791Z

Reserved: 2025-12-15T09:52:45.310Z

Link: CVE-2025-14714

cve-icon Vulnrichment

Updated: 2025-12-15T13:13:12.863Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-15T11:15:39.537

Modified: 2025-12-15T18:22:13.783

Link: CVE-2025-14714

cve-icon Redhat

No data.