Vulnerabilità · 5 ore fa
Homebrew 7.0.0 chiude otto security advisories, ma sette erano già stati riportati nelle release 6.0.x. Per molti ambienti che si auto-aggiornano, il grosso del lavoro era già stato fatto; resta però una falla che si chiude solo con 7.0.0.
La parte rimasta aperta è un LaunchServices sandbox escape: un cask malevolo poteva uscire dal sandbox di installazione di macOS e raggiungere risorse fuori dal perimetro previsto. La 7.0.0 restringe app, Mach services e Unix socket raggiungibili da quel percorso.
Per chi gestisce Homebrew su macOS e installa cask di terze parti, il punto non è la presenza di nuove difese in sé, ma il divario tra auto-update e versione effettiva: solo pre-7.0.0 resta esposto a questa separazione dal sandbox di installazione.
2 fonti che coprono questa storia
Homebrew 7.0.0 is out, here's what changed for security - Help Net Security
Homebrew 7.0.0 security work closes eight advisories, including a cask flaw that reached sudo, and adds a built-in brew vulns scanner.
Homebrew 7.0.0 gets built-in GUI, better security controls
Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical interface.
Part of the PlainSec briefing for 2026-09-15