PatchSiren

sparkle-project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM sparkle-project CVE published 2026-07-21

CVE-2026-47121

The Sparkle software update framework for macOS, prior to version 2.9.2, is vulnerable to an arbitrary file write issue. This defense-in-depth vulnerability allows an attacker with a compromised EdDSA private key to write files at the root level via the delta-apply path. The vulnerability exists in `Autoupdate/SUBinaryDeltaApply.m` and `Autoupdate/SPUSparkleDeltaArchive.m`. The `relativePath.pathComponent [truncated]