Symlink Vulnerability in Sparkle Software Update Framework for macOS
CVE-2026-47121

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-47121?

The Sparkle software update framework for macOS contains a vulnerability that arises from its handling of symbolic links during software updates. Specifically, prior to version 2.9.2, the framework's checks for relative paths allowed for exploitation via maliciously crafted update files. The flaw involves the creation of these links that can escape designated file restrictions based on the resolution of intermediate symlinks. This could allow an attacker with access to a private signing key to perform unauthorized write operations at the root level, significantly elevating the risk of system compromise. Version 2.9.2 addresses this critical issue.

Affected Version(s)

Sparkle < 2.9.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.