I read about a problem with older sparkle. Will there be a Rhino update soon or is this not a issue for Rhino?
Rhino uses Sparkle, but is not vulnerable to this issue. Sparkle can download program updates, and the vulnerability is that the download can be hijacked. Rhino uses Sparkle only to detect when a new version is available, and then redirects you to a McNeel download page in your preferred web browser to download the new version. Sparkle itself does not perform the download.