CVE-2013-3667: Barebones Bbedit

Medium severity, CVSS 6.4. EPSS: 1.8% chance of exploitation in the next 30 days.

The software update mechanism as used in Bare Bones Software Yojimbo before 4.0, TextWrangler before 4.5.3, and BBEdit before 10.5.5 does not properly download and verify updates before installation, which allows attackers to perform "tampering or corruption" of the updates.

Affected products

  • Barebones Bbedit: up to and including 10.5.4; version 10.0 only; version 10.0.1 only; version 10.1 only; version 10.1.1 only; version 10.1.2 only; …
  • Barebones Textwrangler: up to and including 4.5.2; version 2.3 only; version 3.0 only; version 3.1 only; version 3.5 only; version 3.5.1 only; …
  • Barebones Yojimbo: up to and including 3.0.4; version 1.4 only; version 1.4.1 only; version 1.4.2 only; version 1.5 only; version 1.5.1 only; …

Published 2013-12-31. Last modified 2026-06-16.