Executive brief
Sparkle is a widely used software update framework for macOS applications. A vulnerability in how it handles update files could allow an attacker who has compromised a developer's signing key to write files anywhere on a user's system, including protected system directories if the installer is running with administrative privileges. While this requires a stolen signing key to execute, it allows for a much deeper level of system compromise than a standard malicious update would normally permit.
Technical details
A path traversal vulnerability exists in Sparkle's `SUBinaryDeltaApply.m` and `SPUSparkleDeltaArchive.m` components. The framework's delta update mechanism fails to recursively validate all path components for symbolic links. An attacker can craft a `.delta` archive that first creates a symlink pointing to a sensitive system directory (e.g., `/Library/LaunchDaemons`) and then extracts a subsequent file using a path that traverses through that symlink. Because `fopen()` resolves intermediate symlinks, the file is written outside the intended destination tree. Exploitation requires the attacker to possess a valid EdDSA signing key to pass signature verification. If the update process is running as root (system-domain installs), this grants arbitrary root-level file write capabilities. The issue is addressed in version 2.9.2.
Affected products
- sparkle-project Sparkle < 2.9.2
Timeline
- 2026-05-19: advisory: Internal GitHub advisory published
- 2026-07-21: disclosed: NVD publication date