Vulnerability CVE-2024-22405


Published: 2024-04-30

Description:
XADMaster is an objective-C library for archive and file unarchiving and extraction. When extracting a specially crafted zip archive XADMaster may not apply quarantine attribute correctly. Such behaviour may circumvent Gatekeeper checks on the system. Only macOS installations are affected. This issue was fixed in XADMaster 1.10.8. It is recommended to upgrade to the latest version. There are no known workarounds for this issue.

 References:
https://github.com/MacPaw/XADMaster/security/advisories/GHSA-xg3c-r7w5-7xw2
https://github.com/MacPaw/XADMaster/commit/b75c05bc3bca9e183ecd3c512e270ce93006da3c

Copyright 2024, cxsecurity.com

 

Back to Top