negativeSYS.SOURCE: The Hacker News• 2026-09-16T18:44:05+05:30
Parallels Desktop Vulnerability Allows Non-Admin Root Access, Intel Macs Excluded from Fix
A critical vulnerability in Parallels Desktop (CVE-2026-90894) enables non-admin users to escalate to root by exploiting a world-writable socket in the prl_disp_service. Intel Mac users cannot install the fix, as Parallels Desktop 27, which contains the patch, only supports Apple Silicon.
Parallels Desktop for Mac has a flaw that lets an ordinary local account run code as root, the highest level of access on a Mac, software company JFrog said this week.
The attack needs code already running on the machine as a normal user, so it does not work over the network. JFrog says the fix is in Parallels Desktop 27, a version that Intel Macs cannot install.
Yuval Moravchick, who leads
*** END OF TRANSMISSION ***