Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fvpx-gx3c-pq7f

Опубликовано: 16 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 4.8

Описание

The Sparkle framework includes an XPC service Downloader.xpc, by default this service is private to the application its bundled with. A local unprivileged attacker can register this XPC service globally which will inherit TCC permissions of the application. Lack of validation of connecting client allows the attacker to copy TCC-protected files to an arbitrary location. Access to other resources beyond granted-permissions requires user interaction with a system prompt asking for permission.

This issue was fixed in version 2.7.2

The Sparkle framework includes an XPC service Downloader.xpc, by default this service is private to the application its bundled with. A local unprivileged attacker can register this XPC service globally which will inherit TCC permissions of the application. Lack of validation of connecting client allows the attacker to copy TCC-protected files to an arbitrary location. Access to other resources beyond granted-permissions requires user interaction with a system prompt asking for permission.

This issue was fixed in version 2.7.2

EPSS

Процентиль: 4%
0.00019
Низкий

4.8 Medium

CVSS4

Дефекты

CWE-863

Связанные уязвимости

nvd
5 месяцев назад

The Sparkle framework includes an XPC service Downloader.xpc, by default this service is private to the application its bundled with. A local unprivileged attacker can register this XPC service globally which will inherit TCC permissions of the application. Lack of validation of connecting client allows the attacker to copy TCC-protected files to an arbitrary location. Access to other resources beyond granted-permissions requires user interaction with a system prompt asking for permission. This issue was fixed in version 2.7.2

EPSS

Процентиль: 4%
0.00019
Низкий

4.8 Medium

CVSS4

Дефекты

CWE-863