hacker-news · Crawled Sep 16, 2026
Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
2 IoCs
Read original article ↗
AI Summary
A vulnerability in Parallels Desktop for Mac, tracked as CVE-2026-90894 and dubbed ParaShells, allows non-admin local users to gain root privileges by exploiting a world-writable socket and command injection in the prl_disp_service. The flaw affects versions prior to 27.0.0 and is actively exploitable on Apple silicon Macs; however, Intel Macs cannot install the fixed version (27.0.0 or later) due to dropped hardware support. JFrog, which discovered the issue, demonstrated a working exploit involving tar command injection via a maliciously crafted directory path, enabling privilege escalation to root without network access.
AI-extracted · verify before operational use