2024-04-02

liblzma Compromised

The open-source application xz was recently discovered to have been compromised by a backdoor in its liblzma library which potentially allows attackers to take control of a system. The exploit, which affects versions 5.6.0 and 5.6.1 of xz, appears to target only certain Linux distros.

The MacOS build of osabe v0.10.0 is packaged with a version of the liblzma library, but the version of xz this was taken from is 5.4.5, so installs of osabe should be unaffected by this exploit.

Windows builds do not use this library so are unaffected.

I will continue to keep an eye on this and will update this notice if anything changes.