Skip to content

Phosphene

v1.1.1 Security

This release includes 3 security fixes for security teams reviewing exposed deployments.

Published 1mo Media Servers
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 3 known CVEs

Topics

animated-wallpaper desktop-wallpaper macos macos-wallpaper

Summary

AI summary

Validate XPC caller signatures, prevent path traversal, and harden runtime bridging to improve security.

Full changelog

Security and robustness hardening:

  • Harden private WallpaperExtensionKit runtime bridging — guarded casts, bounds-checked runtime writes, and a startup compatibility self-check (#8)
  • Validate library metadata to prevent path traversal (#9)
  • Validate the XPC caller's code signature before accepting wallpaper-host connections (#11)
  • Clean up renderer layers when playback stops (#5)
  • Rotate the extension log so it can't grow unbounded (#4)

Security Fixes

  • Validate XPC caller's code signature before accepting wallpaper-host connections (#11)
  • Validate library metadata to prevent path traversal (#9)
  • Harden private WallpaperExtensionKit runtime bridging with guarded casts, bounds‑checked writes, and startup self‑check (#8)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Phosphene

Get notified when new releases ship.

Sign up free

About Phosphene

All releases →

Beta — feedback welcome: [email protected]