CVE-2017-16895: Arqbackup Arq
High severity, CVSS 7.8. EPSS: 1% chance of exploitation in the next 30 days.
The (1) arq_updater, (2) arqcommitter, (3) standardrestorer, (4) arqglacierrestorer, and (5) arqs3glacierrestorer helper apps in Arq 5.x before 5.10 for Mac allow local users to gain root privileges via a crafted data packet.
Affected products
- Arqbackup Arq: from 5.0.0.65, before 5.10 (fixed in 5.10)
Published 2017-12-01. Last modified 2026-06-17.