Symlink Vulnerability in Sparkle Software Update Framework for macOS
CVE-2026-47121
6.1MEDIUM
What is CVE-2026-47121?
The Sparkle software update framework for macOS contains a vulnerability that arises from its handling of symbolic links during software updates. Specifically, prior to version 2.9.2, the framework's checks for relative paths allowed for exploitation via maliciously crafted update files. The flaw involves the creation of these links that can escape designated file restrictions based on the resolution of intermediate symlinks. This could allow an attacker with access to a private signing key to perform unauthorized write operations at the root level, significantly elevating the risk of system compromise. Version 2.9.2 addresses this critical issue.
Affected Version(s)
Sparkle < 2.9.2
