
VulnTracker@vuln_tracker
A single unescaped URL lets attackers run commands on your Mac through anyquery (CVSS 9.0). CVE-2026-47252 affects anyquery's Brave, Chrome, Edge, Safari and Reminders plugins — a SQL-controlled URL gets interpolated straight into AppleScript/JXA, letting an authenticated user break out and execute OS commands with the anyquery process's privileges. Proof-of-concept exploit code is already public. Fixed in anyquery 0.4.5. Update now. Details: http://vulntracker.io/cves/CVE-2026-47252 #anyquery #CVE #macOS #InfoSec #CyberSecurity
0000070
752 followersView on X
