VulnerabilityModified
CVE-2021-40531
Sketch before 75 allows library feeds to be used to bypass file quarantine.
CRITICAL 9.8EPSS 32.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 32.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opened, without the com.apple.quarantine extended attribute. This results in remote code execution, as demonstrated by CommandString in a terminal profile to Terminal.app.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 32.77% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- sketch/sketch
- Source
- cve@mitre.org
References
- https://jonpalmisc.com/2021/11/22/cve-2021-40531Exploit, Third Party Advisory
- https://www.sketch.com/updates/#version-75Patch, Release Notes, Vendor Advisory
- https://jonpalmisc.com/2021/11/22/cve-2021-40531Exploit, Third Party Advisory
- https://www.sketch.com/updates/#version-75Patch, Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.