{"id":"CVE-2026-47122","summary":"Sparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injection","details":"Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `shouldAcceptNewConnection:` only enforces `SUCodeSigningVerifier validateConnection:` before stage 1 completes. After `_performedStage1Installation = YES`, new connections to the registered Mach service `\u003cbundleId\u003e-spki` are accepted from any local process without team-ID or code-signing checks. As of time of publication, no known patched versions are available.","aliases":["GHSA-g3hp-f6mg-559v"],"modified":"2026-07-25T03:56:16.496329285Z","published":"2026-07-21T13:57:59.824Z","database_specific":{"cwe_ids":["CWE-306","CWE-441"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47122.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47122.json"},{"type":"ADVISORY","url":"https://github.com/sparkle-project/Sparkle/security/advisories/GHSA-g3hp-f6mg-559v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47122"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sparkle-project/sparkle","events":[{"introduced":"0"},{"last_affected":"066e75a8b3e99962685d6a90cdd5293ebffd9261"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"2.9.1"}],"source":"AFFECTED_FIELD"}}],"versions":["2.9.1","2.9.0","2.9.0-beta.2","2.9.0-beta.1","2.8.0","2.8.0-beta.3","2.8.0-beta.2","2.8.0-beta.1","2.7.0","2.7.0-beta.1","2.6.2","2.6.1","2.6.0","2.6.0-beta.2","2.6.0-beta.1","2.5.1","2.5.0","2.5.0-beta.2","2.5.0-beta.1","2.4.2","2.4.1","2.4.1-beta.1","2.4.0","2.4.0-beta.2","2.4.0-beta.1","2.3.0","2.3.0-beta.2","2.3.0-beta.1","2.2.1","2.2.0","2.2.0-beta.2","2.2.0-beta.1","2.1.0","2.1.0-beta.2","2.1.0-beta.1","2.0.0","2.0.0-rc.1","2.0.0-beta.6","2.0.0-beta.5","2.0.0-beta.4","2.0.0-beta.3","2.0.0-beta.2","2.0.0-beta.1","1.14.0rc1","1.12.0","1.12.0a3","1.11.0rc2","1.11.0","1.12.0a2","1.12.0a1","1.11.0rc1","1.10.0rc1","1.10.0","1.9.0","1.9.0rc1","1.8.0","1.7.1","1.7.0","1.6.1","1.6.0","sparkle-1.5b6","sparkle-1.5b5","sparkle-1.5b4","sparkle-1.5b3","sparkle-1.5b2","sparkle-1.5b1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47122.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:L"}]}