CVE-2025-0509: Signing Checks Bypass
A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.
Other sources
A security issue was found in Sparkle before version 2.64. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0509?
CVE-2025-0509 is classified as a high severity vulnerability due to the potential for attackers to manipulate signed updates.
How do I fix CVE-2025-0509?
To fix CVE-2025-0509, update Sparkle to version 2.64 or later to ensure the patch is applied.
What impact does CVE-2025-0509 have on applications using Sparkle?
CVE-2025-0509 allows attackers to potentially replace legitimate updates with malicious payloads, compromising application integrity.
Is CVE-2025-0509 a zero-day vulnerability?
CVE-2025-0509 is not a zero-day vulnerability as it has been publicly disclosed, and patches are available.
Can CVE-2025-0509 affect all versions of Sparkle?
Yes, CVE-2025-0509 affects all versions of Sparkle prior to 2.64.