Western Digital’s EdgeRover desktop app for both Windows and Mac are vulnerable to local privilege escalation and sandboxing escape bugs that could allow the disclosure of sensitive information or denial of service (DoS) attacks. The vulnerability, tracked as CVE-2022-22998, is a directory traversal bug, allowing unauthorized access to restricted directories and files. The flaw was discovered by threat researcher Xavier Danest, who responsibly disclosed it to the vendor. It is unclear if the vulnerability has been actively exploited, Bleeping Computer has contacted the hardware giant to request more details.”]

