Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
- ID
- 25088
- Status
- summarized
- Published
- 16 Sep 2026, 9:14 PM
- Fetched
- 16 Sep 2026, 10:36 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/parallels-desktop-flaw-lets-non-admin.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.0
- Created
- 16 Sep 2026, 10:39 PM
- Tags
- Audience
- developers
What happened
JFrog disclosed a local privilege escalation flaw in Parallels Desktop for Mac (CVE-2026-90894, rated 7.8) that lets any non-admin local account achieve root via a world-writable socket and a tar argument injection in the prl_disp_service. The fix ships only in Parallels Desktop 27, which requires Apple Silicon—meaning Intel Mac users running Parallels 26.4.0 or earlier cannot patch it.
Why it matters
If you develop on an Intel Mac with Parallels Desktop installed, you have an unpatchable local-to-root escalation and should either retire the machine, stop using Parallels on it, or restrict which local accounts exist on that Mac. Apple Silicon Mac users should confirm they are on Parallels 27 or later.
Discussion angle
The Intel-Mac-can't-patch situation is a concrete example of how hardware obsolescence now creates security debt—worth discussing whether your team still has Intel Macs in CI or dev pools and what the migration plan is.