logo

Researchers Warn macOS textutil and KeePassXC Can Become Attack Primitives in Automation

ID: 975f3033-17c0-5c7c-9591-f072c93b25e1

STIX ID: report--975f3033-17c0-5c7c-9591-f072c93b25e1

Feed Name: cybersecurityNews.com

Threat Score
50/100

Date Published: 2026-04-27

Date Updated: 2026-04-27

Author: Tushar Subhra Dutta

...
...

Cipher Security Labs found that macOS textutil will fetch remote resources referenced in HTML inputs—creating an SSRF-like primitive in automated conversion pipelines—and that KeePassXC will perform attacker-controlled, expensive KDF work defined in KDBX metadata, enabling resource-exhaustion attacks against batch-processing systems; both are design/trust-boundary issues (not memory or crypto failures) and the report provides mitigation recommendations including sandboxing, input sanitization, egress restrictions, and KDF parameter limits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.