Medium severity4.2GHSA Advisory· Published Jul 21, 2026· Updated Aug 5, 2026
CVE-2026-47122
CVE-2026-47122
Description
Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, Autoupdate/AppInstaller.m's shouldAcceptNewConnection: only enforces SUCodeSigningVerifier validateConnection: before stage 1 completes. After _performedStage1Installation = YES, new connections to the registered Mach service -spki are accepted from any local process without team-ID or code-signing checks. As of time of publication, no known patched versions are available.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/sparkle-project/SparkleSwiftURL | <= 2.9.1 | — |
Affected products
3<= 2.9.1+ 1 more
- (no CPE)range: <= 2.9.1
- cpe:2.3:a:sparkle-project:sparkle:*:*:*:*:*:*:*:*range: <=2.9.1
Patches
Vulnerability mechanics
References
2- github.com/advisories/GHSA-g3hp-f6mg-559vghsaADVISORY
- github.com/sparkle-project/Sparkle/security/advisories/GHSA-g3hp-f6mg-559vnvdVendor AdvisoryMitigationWEB
News mentions
0No linked articles in our index yet.