Gpgtools provides cryptographic key management and OpenPGP utilities primarily for macOS systems, with its exposure centered on the libmacgpg library component that handles command-line operations. The observed vulnerability pattern reflects input-handling weaknesses, specifically improper neutralization of special elements in command construction, characteristic of systems that bridge user input with shell execution. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gpgtools over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-4677HIGH The installPackage function in the installerHelper subcomponent in Libmacgpg in GPG Suite before 2015.06 allows local users to execute arbitrary commands with root privileges via s | Feb 22, 2017 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gpgtools.
Media articles that mention a CVE ID that affects a product developed by Gpgtools — matched by CVE ID, not by vendor name.