CVE-2017-16895: Arqbackup Arq

High severity, CVSS 7.8. EPSS: 1% chance of exploitation in the next 30 days.

The (1) arq_updater, (2) arqcommitter, (3) standardrestorer, (4) arqglacierrestorer, and (5) arqs3glacierrestorer helper apps in Arq 5.x before 5.10 for Mac allow local users to gain root privileges via a crafted data packet.

Affected products

  • Arqbackup Arq: from 5.0.0.65, before 5.10 (fixed in 5.10)

Published 2017-12-01. Last modified 2026-06-17.