We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
BleachBit cleans files to free disk space and to maintain privacy. BleachBit for Windows up to version 4.6.2 is vulnerable to a DLL Hijacking vulnerability. By placing a malicious DLL with the name uuid.dll in the folder C:\Users\<username>\AppData\Local\Microsoft\WindowsApps\, an attacker can execute arbitrary code every time BleachBit is run. This issue has been patched in version 4.9.0.
Reserved 2025-04-10 | Published 2025-04-15 | Updated 2025-04-15 | Assigner GitHub_MCWE-427: Uncontrolled Search Path Element
github.com/...achbit/security/advisories/GHSA-ghph-v4x4-vr3c
github.com/...ommit/dafeba57dcb14c7ec4a97224ff1408f6b0c2a7f8
Support options