External risk intelligence

Anyquery Command Execution Via Malicious URLs

CVE advisorySeverity: CRITICAL (CVSS 9.0)

CVE-2026-47252

Anyquery is a local SQL engine tool, not an internet-facing gateway or edge service. The vulnerability requires an authenticated user to perform specific actions within a local macOS environment using browser plugins. Public internet exposure of this attack surface is effectively non-existent.

Code Injection

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in Anyquery, an SQL query engine for macOS, that could allow authenticated users to execute operating-system commands through specially crafted URLs. The issue arises from how the software handles URLs within its browser plugins, potentially enabling script injection on the host machine.

  • Command execution via malicious URLs.
  • Concerns authenticated users on macOS.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker begins by gaining authenticated access to a macOS system running Anyquery, specifically requiring INSERT or UPDATE permissions on certain virtual tables. The attacker then crafts a malicious URL containing special characters, which, when processed by the Anyquery Chrome plugin (or its variants in Brave, Edge, or Safari), is interpolated into AppleScript. This allows the attacker to break out of the intended string and inject arbitrary operating-system commands, which then execute with the privileges of the Anyquery process.

  • Authenticated user with INSERT/UPDATE access.
  • Crafted URL triggers script interpolation.
  • Arbitrary command execution.

Live Threat

Current exploitation, exposure, and threat context

Authenticated users with INSERT or UPDATE access to certain macOS virtual tables within Anyquery could execute arbitrary operating system commands. This could occur when a specially crafted URL, containing quote and newline characters, is processed by the Chrome, Brave, Edge, or Safari browser plugins, leading to the interpolation of malicious script statements into AppleScript or JXA code.

  • macOS virtual table data could be at risk.
  • Malicious URLs may break script execution.
  • Arbitrary command execution could occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

The application or platform team responsible for managing Anyquery and its integrations is likely to own this issue. The first practical step is to identify all macOS systems running Anyquery, confirm if the affected browser plugins are in use, and assess the business criticality of those systems. Once identified, the accountable owner should be contacted to plan remediation based on the identified risk.

  • Identify Anyquery instances and plugin usage.
  • Verify affected systems are reachable.
  • Plan remediation with accountable owner.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Anyquery?

Anyquery is an SQL engine built on SQLite that allows users to query various data sources using standard SQL syntax. It includes browser plugins for Chrome, Brave, Edge, and Safari that interact with macOS virtual tables, enabling users to manage browser data through SQL commands.

What does CWE-94 mean for CVE-2026-47252?

CWE-94 refers to improper control of generation of code, often called code injection. In this CVE, the vulnerability occurs because the software fails to sanitize input URLs before inserting them into AppleScript or JXA code. This allows malicious input to escape its intended string and execute unauthorized OS-level commands.

How is this command execution triggered?

An attacker needs authenticated access to perform INSERT or UPDATE operations on specific macOS virtual tables. The bug is triggered when a URL containing quote or newline characters is processed by an affected browser plugin. Simply viewing a website or using the tool without these specific data-modifying permissions does not trigger the vulnerability.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal indicates this is very unlikely to be an internet-facing risk. Because Anyquery functions as a local SQL engine tool rather than a network gateway, an attacker generally cannot reach this surface remotely. Risk is limited to local environments where an attacker has already gained authenticated access.

How do I respond to this Anyquery advisory?

First, inventory your systems to identify where Anyquery and its associated browser plugins are installed on macOS. Assess whether these instances are in use and prioritize updating to version 0.4.5 or later. Coordinate with your team to verify that the fix is applied across all relevant endpoints to mitigate the risk of unauthorized script execution.

References