peter bassill · operator
$ cve CVE-2006-0848 JSON

CVE-2006-0848 EXPLOIT

5.1
MEDIUM · CVSS 2.0 · EPSS 58.1% (pctl 99)

Patch early

A public exploit exists.

Description

The "Open 'safe' files after downloading" option in Safari on Apple Mac OS X allows remote user-assisted attackers to execute arbitrary commands by tricking a user into downloading a __MACOSX folder that contains metadata (resource fork) that invokes the Terminal, which automatically interprets the script using bash, as demonstrated using a ZIP file that contains a script with a safe file extension.

Scoring

CVSS5.1 (MEDIUM, v2.0)
VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
EPSS58.11% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-16
On CISA KEVno
Public exploityes
Published2006-02-22
Last modified2026-06-16

Affected (2)

VendorProduct
applemac os x
applemac os x server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD