hacker-news · Crawled Sep 16, 2026

Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix

2 IoCs
Read original article ↗

AI Summary

A vulnerability in Parallels Desktop for Mac, tracked as CVE-2026-90894 and dubbed ParaShells, allows non-admin local users to gain root privileges by exploiting a world-writable socket and command injection in the prl_disp_service. The flaw affects versions prior to 27.0.0 and is actively exploitable on Apple silicon Macs; however, Intel Macs cannot install the fixed version (27.0.0 or later) due to dropped hardware support. JFrog, which discovered the issue, demonstrated a working exploit involving tar command injection via a maliciously crafted directory path, enabling privilege escalation to root without network access.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
Filename prl_disp_service Details →
Filename prl_disp_service.socket Details →