Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-40531 — Quarantine bypass and RCE vulnerability in Sketch (proof-of-concept) | Kitploit
Tools/GitHubGitHub/jonpalmisc/cve-2021-40531
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubjonpalmisc/cve-2021-40531

CVE-2021-40531

Quarantine bypass and RCE vulnerability in Sketch (proof-of-concept)

View Repository
1224 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

CVE-2021-40531

Exploit Demo

This proof-of-concept in action.

Sketch is a popular UI/UX design app for macOS. This post covers a vulnerability in Sketch that I discovered back in July, CVE-2021-40531. In its simplest form, it is a macOS quarantine bypass, but in context it can be used for remote code execution.

For more details, see my blog post for a complete writeup.

Notes

If you are testing this proof-of-concept locally, be aware that feed.rss expects your web server to be running on port 8080.

Download Tool