Code Injection in Cryptomator - CVE-2022-25366
Published: February 22, 2022
Cryptomator
cryptomator
Description
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to a DYLIB injection flaw. A local user can use a specially crafted .dylib file with DYLD_INSERT_LIBRARIES environment variable and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.