Homebrew 7.0.0 closes eight security advisories, including a High-severity flaw that could let unsigned cask removal metadata run commands with sudo and a Moderate issue involving LaunchServices sandbox escape. The release also adds built-in vulnerability scanning with
brew vulns, expands provenance checks, and tightens sandboxing across macOS and Linux. #Homebrew #LaunchServices #OSV.dev
Keypoints
- Homebrew 7.0.0 fixes eight security advisories.
- The most serious flaw could let unsigned cask removal metadata run commands with sudo.
- Another issue allowed a malicious cask to escape the macOS install sandbox through LaunchServices.
brew vulnsnow checks installed formulae against OSV.dev vulnerability records.- Homebrew strengthens sandboxing, provenance checks, and changes support for Intel Macs and older macOS versions.
Read More: https://www.helpnetsecurity.com/2026/09/15/homebrew-7-0-0-security-open-source/