Sparkle-project Sparkle — known CVE vulnerabilities
Every CVE whose affected-product data names Sparkle-project Sparkle, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (3)
CVE-2025-0509 — CVSS 7.3 (high): A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload…
CVE-2026-47121 — CVSS 6.1 (medium): Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaApply.m` enforces `relativePath.pathCompo…
CVE-2026-47122 — CVSS 4.2 (medium): Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s…