CVE-2025-10015 Details
Description
The Sparkle framework includes an XPC service Downloader.xpc, by default this service is private to the application its bundled with. A local unprivileged attacker can register this XPC service globally which will inherit TCC permissions of the application. Lack of validation of connecting client allows the attacker to copy TCC-protected files to an arbitrary location. Access to other resources beyond granted-permissions requires user interaction with a system prompt asking for permission. This issue was fixed in version 2.7.2
A vulnerability in the Sparkle framework's XPC service, Downloader.xpc, allows local unprivileged attackers to bypass TCC (Transparency, Consent, and Control) protections. By registering the XPC service globally, attackers can exploit the lack of validation on connecting clients to access TCC-protected files and copy them to arbitrary locations. This vulnerability affects all Sparkle versions prior to 2.7.2 and is particularly relevant for sandboxed applications that use the downloader service.
Users can update to Sparkle version 2.7.2 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 16, 2025CISA-ADP
Assessed Sep 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/en/posts/2025/09/CVE-2025-10015 | [email protected] | AdvisoryBundleRemedy |
| https://github.com/sparkle-project/Sparkle | [email protected] | Source CodeVendor |
| https://github.com/sparkle-project/Sparkle/discussions/2764 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Sparkle | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 16, 2025 | New CVE Received | [email protected] |
Volerion