CVE-2025-10016: Local Privilege Escalation in Sparkle Autoupdate Daemon
The Sparkle framework includes a helper tool Autoupdate. Due to lack of authentication of connecting clients a local unprivileged attacker can request installation of crafted malicious PKG file by racing to connect to the daemon when other app spawns it as root. This results in local privilege escalation to root privileges. It is worth noting that it is possible to spawn Autopudate manually via Installer XPC service. However this requires the victim to enter credentials upon system authorization dialog creation that can be modified by the attacker.
This issue was fixed in version 2.7.2
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10016?
CVE-2025-10016 is considered a high severity vulnerability due to the potential for local unprivileged attackers to exploit it.
How do I fix CVE-2025-10016?
To fix CVE-2025-10016, update the Sparkle Autoupdate framework to version 2.7.3 or later where the vulnerability has been addressed.
What are the potential impacts of CVE-2025-10016?
The impact of CVE-2025-10016 includes unauthorized installation of malicious PKG files on systems running affected versions of Sparkle Autoupdate.
Who is affected by CVE-2025-10016?
CVE-2025-10016 affects users running Sparkle Autoupdate versions prior to 2.7.3 on their systems.
When was CVE-2025-10016 disclosed?
CVE-2025-10016 was disclosed in September 2025.