All 5 CVE vulnerabilities found in Sparkle, with AI-generated Chinese analysis, references, and POCs.
Vendor: sparkle-project
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-47122 | Sparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injection CWE-306 | 4.2 | Medium | 2026-07-21 |
| CVE-2026-47121 | Sparkle: Binary delta apply intermediate-symlink traversal in malicious .delta CWE-22 | 6.1 | Medium | 2026-07-21 |
| CVE-2025-10016 | Local Privilege Escalation in Sparkle Autoupdate Daemon CWE-863 | 7.8AI | HighAI | 2025-09-16 |
| CVE-2025-10015 | TCC Bypass via Downloader XPC Service in Sparkle CWE-863 | 6.6AI | MediumAI | 2025-09-16 |
| CVE-2025-0509 | Signing Checks Bypass CWE-552 | 7.3 | High | 2025-02-04 |
All 5 known CVE vulnerabilities affecting Sparkle with full Chinese analysis, references, and POCs where available.