In App-Auto-Patch v3.4.2, insecure file permissions enable a race condition that can be exploited to write arbitrary files. The issue arises from unsafe handling of file creation/modification under permissive permissions, allowing an attacker to win a timing window and redirect or replace the target file being written, resulting in attacker-controlled file contents being written to an arbitrary path.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a proof-of-concept local privilege escalation exploit for CVE-2025-70341 affecting App-Auto-Patch <= 3.4.2 on macOS. The README explains the root cause: App-Auto-Patch/Installomator creates a working directory with world-writable permissions (chmod 777), enabling a TOCTOU race between package signature verification and installation; it also mentions a separate eval-based code execution issue in label parsing, though the included PoC focuses on the TOCTOU package swap. Structure: - README.md: vulnerability description, affected versions, attack chain, and usage notes. - poc.py: main exploit script. Exploit behavior (poc.py): - Runs as an unprivileged user and monitors /var/tmp for directories named Installomator.*. - Checks directory permissions; when it finds a world-writable (777) Installomator directory, it treats it as the target. - Watches the target directory for a downloaded non-hidden .pkg file. - Builds a malicious installer package at /tmp/malicious-payload.pkg using pkgbuild (no payload, only scripts) with a postinstall script that writes /tmp/installomator-pwned. - Uses multiple threads to (1) stage a hidden copy of the malicious package inside the target directory as .m.pkg and (2) repeatedly attempt to delete the legitimate target .pkg and rename the staged malicious .pkg into the victim path, aiming to land the malicious package after verification but before installation. - Declares success when /tmp/installomator-pwned appears and prints its contents. Primary capability: local root code execution via package swap race (TOCTOU) against a privileged App-Auto-Patch/Installomator run. No network IOCs are present; the exploit is purely local and file-system based.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.