---
id: CVE-2025-9815
title: A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS
summary: >-
  A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The
  affected element is an unknown function of the file
  PrivilegeHelper/PrivilegeHelper.swift of the component NSXPCListener. This
  manipulation causes missing aut…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-287
  - CWE-306
  - CWE-306
vendor: alaneuler
product: batterykid
affected:
  - batterykid <= 2.1
published: '2025-09-02'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-9815'
references:
  - url: 'https://github.com/SwayZGl1tZyyy/n-days/blob/main/batteryKid/README.md'
    label: cna@vuldb.com
  - url: >-
      https://github.com/SwayZGl1tZyyy/n-days/blob/main/batteryKid/README.md#proof-of-concepts
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.322142'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.322142'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.641358'
    label: cna@vuldb.com
  - url: 'https://github.com/SwayZGl1tZyyy/n-days/blob/main/batteryKid/README.md'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://github.com/SwayZGl1tZyyy/n-days/blob/main/batteryKid/README.md#proof-of-concepts
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00268
epssPercentile: 0.16878
ingestedAt: '2026-09-26T00:22:39.907Z'
---

## Overview

A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function of the file PrivilegeHelper/PrivilegeHelper.swift of the component NSXPCListener. This manipulation causes missing authentication. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be exploited.

## Affected

- `batterykid <= 2.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
