Home
Description
erase-install prior to v40.4 commit 2c31239 writes swiftDialog credential output to a hardcoded path /var/tmp/dialog.json. This allows an unauthenticated attacker to intercept admin credentials entered during reinstall/erase operations via creating a named pipe.
References
github.com/grahampugh/erase-install/pull/574
github.com/...ommit/2c31239fb8519d87577514b3db9ddb0771232a21
github.com/malvector/CVE-2025-70342