Junglewise Threat Intelligence

CVE-2026-47121: Sparkle path traversal via intermediate symlinks in delta updates

CVE-2026-47121 · Severity: medium · CVSS 6.1 · Published 2026-07-21

Vendors: Swift.

Executive brief

Sparkle is a widely used software update framework for macOS applications. A vulnerability in how it handles update files could allow an attacker who has compromised a developer's signing key to write files anywhere on a user's system, including protected system directories if the installer is running with administrative privileges. While this requires a stolen signing key to execute, it allows for a much deeper level of system compromise than a standard malicious update would normally permit.

Technical details

A path traversal vulnerability exists in Sparkle's `SUBinaryDeltaApply.m` and `SPUSparkleDeltaArchive.m` components. The framework's delta update mechanism fails to recursively validate all path components for symbolic links. An attacker can craft a `.delta` archive that first creates a symlink pointing to a sensitive system directory (e.g., `/Library/LaunchDaemons`) and then extracts a subsequent file using a path that traverses through that symlink. Because `fopen()` resolves intermediate symlinks, the file is written outside the intended destination tree. Exploitation requires the attacker to possess a valid EdDSA signing key to pass signature verification. If the update process is running as root (system-domain installs), this grants arbitrary root-level file write capabilities. The issue is addressed in version 2.9.2.

Affected products

  • sparkle-project Sparkle < 2.9.2

Timeline

  • 2026-05-19: advisory: Internal GitHub advisory published
  • 2026-07-21: disclosed: NVD publication date

References

Related threats