news.mlab.sh
Back to the feed
vulnerability

Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix

HighCVSS 7.8
Image: The Hacker News
Summary

Parallels Desktop has a vulnerability (CVE-2026-90894) that allows non-administrator local accounts on Mac computers to gain root access. The flaw stems from a world-writable socket and a process that allows an attacker to build a passwordless sudo rule. While the fix is in Parallels Desktop 27, Intel Macs cannot install this version, and therefore are not protected. The vulnerability is only exploitable on machines running Parallels Desktop 26.4.0 or earlier, and JFrog has not yet confirmed whether the fix will be backported to older versions.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.