Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a vulnerability in Anyquery, an SQL query engine for macOS, that could allow authenticated users to execute operating-system commands through specially crafted URLs. The issue arises from how the software handles URLs within its browser plugins, potentially enabling script injection on the host machine.
- Command execution via malicious URLs.
- Concerns authenticated users on macOS.
- Confirm relevance and exposure.
Attack Path
How an attacker could exploit the issue
An attacker begins by gaining authenticated access to a macOS system running Anyquery, specifically requiring INSERT or UPDATE permissions on certain virtual tables. The attacker then crafts a malicious URL containing special characters, which, when processed by the Anyquery Chrome plugin (or its variants in Brave, Edge, or Safari), is interpolated into AppleScript. This allows the attacker to break out of the intended string and inject arbitrary operating-system commands, which then execute with the privileges of the Anyquery process.
- Authenticated user with INSERT/UPDATE access.
- Crafted URL triggers script interpolation.
- Arbitrary command execution.
Live Threat
Current exploitation, exposure, and threat context
Authenticated users with INSERT or UPDATE access to certain macOS virtual tables within Anyquery could execute arbitrary operating system commands. This could occur when a specially crafted URL, containing quote and newline characters, is processed by the Chrome, Brave, Edge, or Safari browser plugins, leading to the interpolation of malicious script statements into AppleScript or JXA code.
- macOS virtual table data could be at risk.
- Malicious URLs may break script execution.
- Arbitrary command execution could occur.
Operational Fix
Recommended remediation, mitigation, and detection steps
The application or platform team responsible for managing Anyquery and its integrations is likely to own this issue. The first practical step is to identify all macOS systems running Anyquery, confirm if the affected browser plugins are in use, and assess the business criticality of those systems. Once identified, the accountable owner should be contacted to plan remediation based on the identified risk.
- Identify Anyquery instances and plugin usage.
- Verify affected systems are reachable.
- Plan remediation with accountable owner.