CVE-2023-41902: Corecode Macupdater
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
An XPC misconfiguration vulnerability in CoreCode MacUpdater before 2.3.8, and 3.x before 3.1.2, allows attackers to escalate privileges by crafting malicious .pkg files.
Affected products
- Corecode Macupdater: before 2.3.8 (fixed in 2.3.8); from 3.0.0, before 3.1.2 (fixed in 3.1.2)
Published 2023-09-20. Last modified 2026-06-17.