PT-2026-45558 · Steipete+1 · Codexbar
CVSS v4.0
7.2
High
| Vector | AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
CodexBar versions prior to 0.32.0
Description
Insecure temporary file handling in the release notarization workflow allows local attackers to access sensitive credentials or tamper with build artifacts. This is possible by exploiting predictable file paths, enabling attackers on the same host to read the App Store Connect API key written to a fixed path. Additionally, attackers can pre-create files or symbolic links at predictable locations to redirect writes to attacker-controlled destinations or modify notarization archives before they are submitted.
Recommendations
Update CodexBar to version 0.32.0 or later.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Codexbar