Executive brief
CodexBar is a macOS utility that includes a command-line interface (CLI) installer. A security flaw in the installer allows a malicious program already on the computer to hijack the installation process. If a user attempts to install the CLI tool and provides their administrator password when prompted, the malicious program can trick the system into running its own commands with full root privileges, potentially leading to a complete system takeover.
Technical details
A local privilege escalation vulnerability exists in the CodexBar CLI installer (bin/install-codexbar-cli.sh) due to insecure temporary file handling (CWE-377). The installer uses `mktemp` to create a shell script in a user-writable directory, populates it with installation commands, and then executes it via AppleScript's `do shell script` with administrator privileges. Because the temporary file remains owned and mutable by the unprivileged user, a malicious process running as the same user can monitor the filesystem and overwrite the script's contents during the window when the user is prompted for credentials. This race condition allows the attacker to execute arbitrary commands as root once the user approves the legitimate elevation prompt. The issue is resolved in version 0.32.0 by moving the command logic into an immutable AppleScript string.
Affected products
- steipete CodexBar < 0.32.0
Timeline
- 2026-05-30: patched: Fix merged in pull request 1222
- 2026-05-31: advisory: Version 0.32.0 released
- 2026-06-01: disclosed: CVE-2026-49134 published