Junglewise Threat Intelligence

CVE-2026-47122: Sparkle missing authentication in AppInstaller Mach service connection

CVE-2026-47122 · Severity: medium · CVSS 4.2 · Published 2026-07-21

Vendors: Swift.

Executive brief

Sparkle is a widely used software update framework for macOS applications. A security flaw in the update process allows a malicious local program to bypass security checks and inject fake update information during a specific stage of the installation. While this does not allow the attacker to install malicious code, it enables them to display fraudulent release notes, version numbers, and 'critical update' flags to the user, potentially leading to social engineering or misinformation.

Technical details

A missing authentication vulnerability exists in Sparkle's `Autoupdate/AppInstaller.m` within the `shouldAcceptNewConnection:` method. The framework only enforces `SUCodeSigningVerifier` validation before the `_performedStage1Installation` flag is set to true. Once stage 1 completes, the registered Mach service (`<bundleId>-spki`) accepts connections from any local process without verifying Team ID or code signatures. An attacker can exploit a tight timing window—specifically if the legitimate updating app crashes or exits before sending final data—to inject a spoofed `SPUSentUpdateAppcastItemData` payload. This results in the Sparkle progress agent broadcasting attacker-controlled metadata (name, version, release notes) to other Sparkle-aware applications on the system. No patch was available at the time of publication.

Affected products

  • sparkle-project Sparkle <= 2.9.1

Timeline

  • 2026-05-19: advisory: GitHub Security Advisory published
  • 2026-07-21: disclosed: NVD publication date

References

Related threats