CVE Tools

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)

Help Net SecurityBy Zeljka Zorz

PoC publicParallels Desktop

Our summary

A public proof of concept has highlighted CVE-2026-90894, also known as ParaShells, an argument injection issue in Parallels Desktop for Mac v26.4.0 on Apple ARM-based macOS systems. A low-privileged local user can abuse the root-running prl_disp_service to obtain root access, potentially exposing other users' data and enabling persistence; Parallels fixed the flaw in Parallels Desktop v27.0.0, so organizations should upgrade.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store