Local Process Vulnerability in Sparkle Software Update Framework for macOS
CVE-2026-47122
4.2MEDIUM
What is CVE-2026-47122?
The Sparkle software update framework, utilized for macOS applications, presents a security flaw in versions up to and including 2.9.1. Specifically, the method responsible for managing new connections fails to properly enforce team-ID and code-signing checks after the first installation stage is completed. This oversight allows any local process to establish a connection with the registered Mach service without adequate validation, potentially leading to unauthorized access and exposure of sensitive data. No patches are currently available to mitigate this vulnerability.
Affected Version(s)
Sparkle <= 2.9.1
