Impact
Anyquery is an SQL query engine that uses SQLite. Prior to version 0.4.5, the macOS plugins for Brave, Chrome, Edge, Reminders, and Safari included code that interpolates a user‑controlled URL into AppleScript or JavaScript for Automation (JXA) source that is then executed by osascript. When an authenticated user has INSERT or UPDATE access to the affected virtual tables, a specially crafted URL containing quote or newline characters can break out of the intended string context and inject additional script statements. This injection allows the attacker to execute arbitrary operating‑system commands with the privileges of the anyquery process, thereby compromising the integrity of the host system.
Affected Systems
Anyquery plugins for Brave, Chrome, Edge, Reminders, and Safari shipped in any releases before version 0.4.5 are affected. The CVE covers the anyquery engine itself and its macOS plugin interface; all prior releases containing the unescaped URL formatting are vulnerable.
Risk and Exploitability
The CVSS score of 9 signals critical severity. The EPSS score of less than 1% indicates a low likelihood of exploitation at the time of assessment, and the vulnerability is not listed in CISA’s KEV catalog. However, the exploit requires an authenticated user with INSERT or UPDATE capability on the virtual tables, a privilege that may exist in shared or multi‑tenant deployments. Successful exploitation would give the attacker full control over arbitrary commands on the host, making mitigation a priority despite the low exploitation probability.
OpenCVE Enrichment
Github GHSA