PatchSiren cyber security CVE debrief
CVE-2026-47121 sparkle-project CVE debrief
The Sparkle software update framework for macOS, prior to version 2.9.2, is vulnerable to an arbitrary file write issue. This defense-in-depth vulnerability allows an attacker with a compromised EdDSA private key to write files at the root level via the delta-apply path. The vulnerability exists in `Autoupdate/SUBinaryDeltaApply.m` and `Autoupdate/SPUSparkleDeltaArchive.m`. The `relativePath.pathComponents` check only rejects writes whose immediate parent directory is a symbolic link, but does not detect symlinks deeper in the relative path. The `extractItem:` method creates symlinks in the destination tree from archive content without a `..` check on the symlink target. A subsequent `Extract` item targeting `<symlink>/foo/bar` can escape the destination tree via `fopen(path, 'wb')`, allowing an attacker to write files at the root level. macOS users and administrators who utilize the Sparkle software update framework, particularly those with system-domain installs, should be aware of this vulnerability and take steps to update to version 2.9.2 or later.
- Vendor
- sparkle-project
- Product
- Sparkle
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-22
Who should care
macOS users and administrators who utilize the Sparkle software update framework, particularly those with system-domain installs, should be aware of this vulnerability and take steps to update to version 2.9.2 or later. Affected operators, platforms, vulnerability-management, and security teams should review and act on this vulnerability.
Technical summary
The vulnerability exists in `Autoupdate/SUBinaryDeltaApply.m` and `Autoupdate/SPUSparkleDeltaArchive.m`. The `relativePath.pathComponents` check only rejects writes whose immediate parent directory is a symbolic link, but does not detect symlinks deeper in the relative path. The `extractItem:` method creates symlinks in the destination tree from archive content without a `..` check on the symlink target. A subsequent `Extract` item targeting `<symlink>/foo/bar` can escape the destination tree via `fopen(path, 'wb')`, allowing an attacker to write files at the root level.
Defensive priority
High
Recommended defensive actions
- Update Sparkle to version 2.9.2 or later
- Verify the integrity of the Sparkle installation and ensure the AppInstaller is not running with elevated privileges
- Monitor for suspicious activity and implement compensating controls to prevent exploitation
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
Evidence notes
The CVE record was published on 2026-07-21T14:16:34.387Z and was last modified on 2026-07-22T15:17:16.413Z. The NVD entry is currently MEDIUM. The Sparkle software update framework for macOS, prior to version 2.9.2, is vulnerable to an arbitrary file write issue due to a defense-in-depth vulnerability. This vulnerability allows an attacker with a compromised EdDSA private key to write files at the root level via the delta-apply path. The CVE record was published on 2026-07-21T14:16:34.387Z and has not been modified since then.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T14:16:34.387Z and has not been modified since then. The NVD entry is currently MEDIUM.