erase-install versions prior to v40.4 (commit 2c31239) write swiftDialog credential output to a hardcoded, predictable path (/var/tmp/dialog.json). Because the file path is in a world-writable temporary directory and is not safely created/validated, an unauthenticated local attacker can pre-create the path as a named pipe (FIFO) and thereby intercept administrator credentials entered during reinstall/erase operations when erase-install writes the credential output.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a PoC for CVE-2025-70342 affecting erase-install (<= v40.4) on macOS Apple Silicon. The vulnerability is a predictable, hardcoded credential output file in a world-writable directory (/var/tmp/dialog.json) where swiftDialog output (including admin credentials) is redirected. The PoC (poc.py) implements a local credential interception attack by: (1) creating a named pipe FIFO at /tmp/.dialog-fifo, (2) deleting any existing /var/tmp/dialog.json and creating a symlink from /var/tmp/dialog.json to the FIFO, then (3) blocking on reading the FIFO and printing whatever erase-install writes when an admin runs erase-install and enters credentials. A cleanup mode removes the symlink and FIFO. No network activity is present; the exploit is purely local and relies on user interaction (admin entering credentials) and the target’s use of the vulnerable hardcoded path.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.