EIP-2026-104607
PRE-CVEXcode OpenBase 9.1.5 (OSX) - Local Privilege Escalation
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104607. PoCs published by Kevin Finisterre.
AI-analyzed exploit summary This exploit leverages a vulnerability in OpenBase (bundled with Xcode) where the binary calls gnutar with elevated privileges. By manipulating the PATH environment variable and TAR_OPTIONS, it tricks the system into executing a malicious 'gzip' binary, leading to root privilege escalation.
Description
Xcode OpenBase 9.1.5 (OSX) - Local Privilege Escalation
Exploits (1)
This exploit leverages a vulnerability in OpenBase (bundled with Xcode) where the binary calls gnutar with elevated privileges. By manipulating the PATH environment variable and TAR_OPTIONS, it tricks the system into executing a malicious 'gzip' binary, leading to root privilege escalation.