AI Weekly Malaysia

Back to items Summaries

Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix

ID
25088
Status
summarized
Published
16 Sep 2026, 9:14 PM
Fetched
16 Sep 2026, 10:36 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/parallels-desktop-flaw-lets-non-admin.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
4.0
Created
16 Sep 2026, 10:39 PM
Tags
Audience
developers

What happened

JFrog disclosed a local privilege escalation flaw in Parallels Desktop for Mac (CVE-2026-90894, rated 7.8) that lets any non-admin local account achieve root via a world-writable socket and a tar argument injection in the prl_disp_service. The fix ships only in Parallels Desktop 27, which requires Apple Silicon—meaning Intel Mac users running Parallels 26.4.0 or earlier cannot patch it.

Why it matters

If you develop on an Intel Mac with Parallels Desktop installed, you have an unpatchable local-to-root escalation and should either retire the machine, stop using Parallels on it, or restrict which local accounts exist on that Mac. Apple Silicon Mac users should confirm they are on Parallels 27 or later.

Discussion angle

The Intel-Mac-can't-patch situation is a concrete example of how hardware obsolescence now creates security debt—worth discussing whether your team still has Intel Macs in CI or dev pools and what the migration plan is.

Top