Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
PoC publicParallels Desktop for MacOur summary
A public PoC for CVE-2026-90894 shows how a non-admin local user can gain root privileges on a Mac running vulnerable Parallels Desktop for Mac. The flaw abuses appliance extraction to inject tar options through the root-run prl_disp_service, affecting builds below Parallels Desktop 27.0.0. JFrog identifies version 27.0.0 as fixed, but Intel Macs cannot install the 27.x line and may remain without a confirmed fix on Parallels Desktop 26.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.