CVE-2018-10406: High severity yelp vulnerability
An issue was discovered in Yelp OSXCollector. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the malicious unsigned code will execute.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10406?
CVE-2018-10406 is considered a critical vulnerability due to its ability to bypass third-party code signing checks.
How do I fix CVE-2018-10406?
To fix CVE-2018-10406, upgrade to version 1.10 or higher of the osxcollector package.
What software is affected by CVE-2018-10406?
CVE-2018-10406 affects the Yelp osxcollector package versions prior to 1.10.
How does CVE-2018-10406 exploit the code signing process?
CVE-2018-10406 exploits the code signing process by allowing crafted Universal/fat binaries to evade checks and appear as if they are signed by Apple.
Who is impacted by CVE-2018-10406?
Users of third-party tools utilizing osxcollector prior to version 1.10 are impacted by CVE-2018-10406.