Security researchers have shown that a malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker’s code as soon as it is opened, with none of the warning either program shows before running a macro, The Hacker News reported on 6 October 2026. LibreOffice has been patched; Apache OpenOffice has not [1].
Background
LibreOffice and Apache OpenOffice are free office suites that also run on macOS. Both warn the user before a document runs a macro, and many people rely on that prompt as the sign that a file is trusted.
Findings
The attack combines legitimate features. A spreadsheet defines a “database range” that refreshes from an external source and points to an ODB (OpenOffice database) file at a web address. The ODB names a Java database driver (JDBC) and its location, and the program downloads and loads the driver, which is attacker-controlled code. The researchers say the chain reaches code execution “without ever asking the user to trust the document” [1]. Java support must be enabled for the attack to work [1].
LibreOffice’s flaw is CVE-2026-63277, credited to Rick de Jager of V12 and to Thomas Rinsma and Edoardo Geraci of Codean Labs, and is fixed in versions 26.2.5 and 26.8.0. The Apache OpenOffice flaw is CVE-2026-59265, found by Codean Labs, and affects versions up to and including 4.1.16; a fix in 4.1.17 is still in testing. OpenOffice was notified on 2 October and LibreOffice released patches on 5 October 2026. Caolán McNamara of Collabora Productivity developed the LibreOffice fix [1].
Implications for Mac users
The article states that the flaw is not tied to one operating system. The researchers’ testing covered Windows and Linux, and the article does not mention macOS testing [1]. Mac users of either suite should therefore treat the issue as possibly applicable and not assume exemption.
Recommendations
- Update LibreOffice to 26.2.5 or 26.8.0 or later.
- In Apache OpenOffice, disable Java in the program settings until 4.1.17 is released, as the article advises.
- Avoid opening spreadsheets from unknown senders in either suite, and treat the absence of a macro warning as no assurance of safety.
- Check a downloaded file’s source before opening it, and prefer a preview in a viewer that does not run external content.
Relevance to FireAI
FireAI asks before an app connects to a destination for which no rule exists, and shows the app, the destination and, where it can tell, the country and company, so a first connection from an office suite is visible. It identifies apps by code signature, so a prompt that says an app was modified since it was signed is a prompt to be careful. If a rule already allows the suite to connect, no prompt appears. FireAI does not scan documents, does not fix vulnerabilities and does not stop code from running once it has started.
Limitations
The article does not report exploitation in the wild, and it does not state whether the attack was tested on macOS. The OpenOffice fix date is not fixed, since 4.1.17 is still in testing [1]. Details beyond the article, such as severity scores, are not given here.
To see which apps connect from a Mac, download FireAI and try it free for 17 days. FireAI is made by HisnLabs.