Sparkle Project maintains a software-update framework for macOS applications, a narrowly scoped product that serves as a foundational component across a range of desktop software. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sparkle Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-0509MEDIUM A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks. | Feb 4, 2025 | 6.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sparkle Project.
Media articles that mention a CVE ID that affects a product developed by Sparkle Project — matched by CVE ID, not by vendor name.