← Back to feed
Vulnerabilities & PatchesEmerging1 sourceJul 29, 2026 · 17:25via CERT/CC Vulnerability Notes

VU#293714: Arbitrary File Overwrite in Develar app-builder (zipx.Unzip) via Symlink Following on macOS (APFS)

Brief

Overview

A vulnerability in the zipx. Unzip extraction routine of Develar’s app-builder allows an attacker to overwrite arbitrary files on macOS using Apple File System (APFS). The issue arises from a combination of Unicode normalization collisions and unsafe symlink-following behavior. APFS treats certain Unicode equivalent filenames as identical (e. g.

, ß ↔ ss), while app builder performs no canonical normalization before validating or writing paths.

Description

Develar’s app-builder is a command‑line build tool used heavily in the Electron ecosystem to package, sign, notarize, and produce distributable application bundles for macOS, Windows, and Linux. It is popular because it is a transitive dependency of electron-builder, one of the most widely used packaging tools for Electron apps.

The vulnerability arises from how the zipx.

Read more on CERT/CC Vulnerability Notes