Bypass of Signing Checks in Sparkle Update Framework
CVE-2025-0509
6.8MEDIUM
What is CVE-2025-0509?
A security flaw in the Sparkle update framework prior to version 2.64 allows an attacker to substitute a legitimate signed update with a malicious payload. This vulnerability undermines the integrity of software updates by bypassing Sparkle’s (Ed)DSA signing mechanisms, potentially leading to unauthorized code execution.
Affected Version(s)
Sparkle MacOS 0 < 2.6.4
