RAR Extractor - Unarchiver Free and Pro version 6.4.0 for MacOS contains a vulnerability in the exploit_combined.dylib component that allows local attackers to inject arbitrary code. This can result in the execution of attacker-controlled code within the context of the application, potentially leading to remote control and unauthorized access to sensitive user data.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository demonstrates a local code injection exploit for CVE-2024-55504, targeting RAR Extractor - Unarchiver Free and Pro v6.4.0 on macOS. The exploit leverages the DYLD_INSERT_LIBRARIES environment variable to inject a malicious dynamic library (not included in the repository, but referenced as 'exploit_combined.dylib') into the target application's process. The provided Objective-C code (main8.m) defines a constructor function that executes upon library load, printing a success message and launching a shell command to read the first 20 lines of /etc/passwd, demonstrating arbitrary code execution. The README provides clear reproduction steps and references. The exploit is a proof-of-concept and does not include a weaponized payload, but it effectively demonstrates the vulnerability's impact. The main fingerprintable endpoints are the target application binary and the /etc/passwd file accessed by the payload.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.