Executive brief
Canon My Image Garden is a photo management and printing application for macOS. A vulnerability in its installer allows a local user to manipulate file permissions on the system by using specially crafted symbolic links during the installation process. This could allow an unauthorized person to gain control over files they should not be able to access, potentially compromising the integrity of the system.
Technical details
A 'Link Following' vulnerability (CWE-59) exists in the installer for Canon My Image Garden for macOS version 3.6.8 and earlier. The installer fails to properly validate symbolic links during the installation process. A local attacker with login privileges can create a specially crafted symbolic link that the installer follows, leading to the modification of permissions for arbitrary files or directories. This exploit requires user interaction (running the installer) and allows the attacker to gain unauthorized write access or control over sensitive system files. Canon has released version 3.6.8a to address this issue.
Affected products
- Canon My Image Garden 3.6.8 and earlier
Timeline
- 2026-05-28: advisory: Canon PSIRT published advisory CP2026-004
- 2026-05-28: patched: Version 3.6.8a released to address the vulnerability
- 2026-05-29: disclosed: CVE-2026-6891 published to NVD
References
- https://canon.jp/support/support-info/260528-2vulnerability-response
- https://psirt.canon/advisory-information/cp2026-004/
- https://www.canon-europe.com/support/product-security/
- https://www.usa.canon.com/support/canon-product-advisories/CPA2026-004-Vulnerability-Remediation-for-My-Image-Garden-for-macOS-and-CUPS-Printer-Driver-for-macOS