Sparklabs develops Viscosity, a VPN client application whose vulnerability footprint centers on path-handling and search-path control issues. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sparklabs over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4284CRITICAL A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the setuid-set ViscosityHelper binary, which could let a remote ma | Jan 10, 2020 | 9.8 | 84 | NO | YES |
CVE-2017-20123HIGH A vulnerability was found in Viscosity 1.6.7. It has been classified as critical. This affects an unknown part of the component DLL Handler. The manipulation leads to untrusted sea | Jun 30, 2022 | 7.8 | 26 | NO | NO |
CVE-2020-5180HIGH Viscosity 1.8.2 on Windows and macOS allows an unprivileged user to set a subset of OpenVPN parameters, which can be used to load a malicious library into the memory of the OpenVPN | Jan 14, 2020 | 7.8 | 24 | NO | NO |
CVE-2025-4412MEDIUM On macOS systems, by utilizing a Launch Agent and loading the viscosity_openvpn process from the application bundle, it is possible to load a dynamic library with Viscosity's TCC ( | May 27, 2025 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sparklabs.
Media articles that mention a CVE ID that affects a product developed by Sparklabs — matched by CVE ID, not by vendor name.