Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Homebrew’s 2023 security audit identified 25 findings. In its 2024 status update, Homebrew reported 16 fixed, 3 in progress and 6 acknowledged. The audit was conducted by Trail of Bits and funded by the Open Technology Fund (OTF). It found weaknesses involving sandboxing, path traversal, CI/CD trust and other areas, but it was a time-limited review of specified components—not a certification of every part of Homebrew or a guarantee about its security today.

What the audit found

Trail of Bits carried out the white-box audit in August 2023 with access to source code and documentation. OTF says the review used static and dynamic testing. Homebrew’s 2024 summary recorded 25 findings in total.

Severity breakdown

Homebrew’s 2024 summary assigned the findings these severity ratings:

Severity Number of findings
High 0
Medium 14
Low 2
Informational 7
Undetermined 2

These are the ratings in Homebrew’s summary; they describe the audit findings, not the risk of every possible Homebrew vulnerability or the state of the software today.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
  • Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
  • Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
  • Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)

Types of weaknesses

Homebrew’s remediation list includes path traversal during file caching, a sandbox escape through string injection, an overly permissive default sandbox rule, handling of special characters in package names and versions, and weak cryptographic digest use in Formulary namespaces. OTF also groups concerns around sandbox escapes, CI/CD compromise avenues and unclear threat modeling that relied heavily on manual review. SecurityWeek’s contemporaneous coverage describes related issues including insufficient checks, privilege escalation and legacy code.

Were all 25 findings fixed?

No—not according to Homebrew’s 2024 status snapshot. Homebrew reported 16 fixed, 3 in progress and 6 acknowledged:

Status in Homebrew’s 2024 update Number of findings
Fixed 16
In progress 3
Acknowledged 6

Those figures are historical. They do not establish the present status of each finding, and they should not be read as a description of Homebrew’s code after the 2024 update.

What was included—and what was not

The reviewed areas were Homebrew/brew, Homebrew/actions, formulae.brew.sh and homebrew-test-bot. OTF describes the focus as the core package manager, build-automation functions and formula JSON API.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

OTF says the engagement was time-boxed and did not include a full evaluation of Homebrew’s test suite, all dependencies or logging completeness. The findings therefore apply to the surfaces and work examined; the audit does not establish that every component, dependency or possible attack path was reviewed.

Does the audit mean Homebrew is safe to use now?

The audit is useful evidence about particular Homebrew components at the time they were reviewed. It cannot by itself certify Homebrew as safe today. Its 2023 testing and 2024 remediation snapshot are historical, and subsequent changes or newly reported issues require separate consideration.

Homebrew’s public advisory index continued to show advisories in September 2026, including a high-severity package postinstall issue and moderate- or low-severity cask and sandbox issues. Their appearance shows that security work continued; it does not, on its own, establish whether a particular installation is affected or whether an issue remains unresolved. For a present-day assessment, check Homebrew’s current security advisories alongside the audit rather than relying on the 2023 findings alone.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to report a suspected Homebrew vulnerability

Homebrew’s security policy asks researchers to report suspected vulnerabilities privately. It also says public vulnerability research requires prior written approval. Anyone who believes they have found a vulnerability should follow the current policy’s reporting instructions and avoid publishing details before receiving the required approval.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

Bestseller No. 1
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
Made in USA - Proudly produced in Ohio by a Veteran-owned business
$22.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.