MEDIUM
sparkle-project
CVE published 2026-07-21
CVE-2026-47121
The Sparkle software update framework for macOS, prior to version 2.9.2, is vulnerable to an arbitrary file write issue. This defense-in-depth vulnerability allows an attacker with a compromised EdDSA private key to write files at the root level via the delta-apply path. The vulnerability exists in `Autoupdate/SUBinaryDeltaApply.m` and `Autoupdate/SPUSparkleDeltaArchive.m`. The `relativePath.pathComponent [truncated]