Description
Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of files for which they would not normally have authorization.
Problem types
CWE-59 Improper link resolution before file access ('link following')
Product status
3.6.8 or earlier
References
psirt.canon/advisory-information/cp2026-004/
canon.jp/support/support-info/260528-2vulnerability-response
www.usa.canon.com/...macOS-and-CUPS-Printer-Driver-for-macOS
www.canon-europe.com/support/product-security/