Vulnerability Management

Parallels Desktop flaw allows local users to gain root access

The Hacker News reports that a critical vulnerability, dubbed ParaShells, has been discovered in Parallels Desktop for Mac, potentially allowing ordinary local user accounts to execute commands with root privileges.

Software company JFrog disclosed the flaw, tracked as CVE-2026-90894, which affects versions prior to Parallels Desktop 27. The vulnerability stems from a background service, prl_disp_service, that runs as root and has a world-writable socket. An attacker with code already running on the machine as a normal user can exploit this by injecting commands into the tar archive extraction process. This allows them to execute arbitrary commands as root, potentially leading to a full system compromise.

The flaw impacts the Mac host itself, not the virtual machines. While JFrog rates the vulnerability at 7.8 out of 10, no attacks have been reported. The fix is available in Parallels Desktop 27, but this version is only compatible with Apple silicon Macs running macOS Sonoma 14.7 or newer. Intel Mac users are advised to remain on Parallels Desktop 26, which does not contain the fix, and to limit local user access and monitor for suspicious activity.

Source: The Hacker News

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds