CVE-2025-10016 - CVE House
Back to Database
Status published High CVE-2025-10016

Local Privilege Escalation in Sparkle Autoupdate Daemon

Vulnerability Description

The Sparkle framework includes a helper tool Autoupdate. Due to lack of authentication of connecting clients a local unprivileged attacker can request installation of crafted malicious PKG file by racing to connect to the daemon when other app spawns it as root. This results in local privilege escalation to root privileges. It is worth noting that it is possible to spawn Autopudate manually via Installer XPC service. However this requires the victim to enter credentials upon system authorization dialog creation that can be modified by the attacker. This issue was fixed in version 2.7.2

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-10016

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Karol Mazurek - Afine Team

Affected Vendor

Sparkle Project

View all reports →

Affected Software

Sparkle
Vulnerable Versions:
0

Timeline

Official Publish: September 16th, 2025
Last Modified: September 16th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)