Story thread · 2 reports / 2 sources

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)

helpnetsecurity.com · 3h · first report

A newly disclosed vulnerability in Parallels Desktop, tracked as CVE-2026-90894 and dubbed “ParaShells,” can allow any local user on a Mac to gain root privileges on the host system. ParaShells PoC in action (Source: JFrog) The danger is highest on developer laptops, where a single poisoned Homebrew formula or malicious npm preinstall script can go from local user to full control, and on shared university and corporate machines that have many local accounts, JFrog vulnerability … More → The post Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894) appeared first on Help Net Security .

The coverage

  1. Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix

    thehackernews.com · 2h

The conversation · 0

Sign in to join the conversation.

No comments yet — start the thread.