This release includes 3 security fixes for security teams reviewing exposed deployments.
Published 1mo
Media Servers
✓ No known CVEs patched
This release patches 3 known CVEs
Topics
animated-wallpaper
desktop-wallpaper
macos
macos-wallpaper
Summary
AI summaryValidate XPC caller signatures, prevent path traversal, and harden runtime bridging to improve security.
Full changelog
Security and robustness hardening:
- Harden private WallpaperExtensionKit runtime bridging — guarded casts, bounds-checked runtime writes, and a startup compatibility self-check (#8)
- Validate library metadata to prevent path traversal (#9)
- Validate the XPC caller's code signature before accepting wallpaper-host connections (#11)
- Clean up renderer layers when playback stops (#5)
- Rotate the extension log so it can't grow unbounded (#4)
Security Fixes
- Validate XPC caller's code signature before accepting wallpaper-host connections (#11)
- Validate library metadata to prevent path traversal (#9)
- Harden private WallpaperExtensionKit runtime bridging with guarded casts, bounds‑checked writes, and startup self‑check (#8)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Phosphene
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]