The Hacker News reports that a critical vulnerability, dubbed ParaShells, has been discovered in Parallels Desktop for Mac, potentially allowing ordinary local user accounts to execute commands with root privileges.Software company JFrog disclosed the flaw, tracked as CVE-2026-90894, which affects versions prior to Parallels Desktop 27. The vulnerability stems from a background service, prl_disp_service, that runs as root and has a world-writable socket. An attacker with code already running on the machine as a normal user can exploit this by injecting commands into the tar archive extraction process. This allows them to execute arbitrary commands as root, potentially leading to a full system compromise.The flaw impacts the Mac host itself, not the virtual machines. While JFrog rates the vulnerability at 7.8 out of 10, no attacks have been reported. The fix is available in Parallels Desktop 27, but this version is only compatible with Apple silicon Macs running macOS Sonoma 14.7 or newer. Intel Mac users are advised to remain on Parallels Desktop 26, which does not contain the fix, and to limit local user access and monitor for suspicious activity.Source: The Hacker News
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
