CVE-2024-53407

LOW

Phiewer 4.1.0 - Untrusted Search Path Leading to Command Execution via Dylib Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-53407. PoCs published by SyFi.

AI-analyzed exploit summary This PoC demonstrates a dylib injection vulnerability in Phiewer 4.1.0 on macOS, allowing local command execution via the DYLD_INSERT_LIBRARIES environment variable. The exploit requires a malicious .dylib file to be injected into the target application.

Description

In Phiewer 4.1.0, a dylib injection leads to Command Execution which allow attackers to inject dylib file potentially leading to remote control and unauthorized access to sensitive user data.

Exploits (1)

nomisec WORKING POC
by SyFi · poc
https://github.com/SyFi/CVE-2024-53407

This PoC demonstrates a dylib injection vulnerability in Phiewer 4.1.0 on macOS, allowing local command execution via the DYLD_INSERT_LIBRARIES environment variable. The exploit requires a malicious .dylib file to be injected into the target application.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Phiewer 4.1.0
No auth needed
Prerequisites: Access to the target macOS system · Malicious .dylib file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 3.3
EPSS 0.0051
EPSS Percentile 39.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-426
Status published
Products (1)
phiewer/phiewer 4.1.0
Published Jan 15, 2025
Tracked Since Feb 18, 2026