CVE Tools

Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix

The Hacker NewsBy The Hacker News

PoC publicParallels Desktop for Mac

Our summary

A public PoC for CVE-2026-90894 shows how a non-admin local user can gain root privileges on a Mac running vulnerable Parallels Desktop for Mac. The flaw abuses appliance extraction to inject tar options through the root-run prl_disp_service, affecting builds below Parallels Desktop 27.0.0. JFrog identifies version 27.0.0 as fixed, but Intel Macs cannot install the 27.x line and may remain without a confirmed fix on Parallels Desktop 26.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store