CuraSec

Plan active

Parallels Desktop LPE: Intel Macs Left Without Patch Path

2026-09-16 15:25 UTC · The Hacker News · read the source ↗ #local-privilege-escalation#macos#parallels
  • Engineer — Plan: Upgrade Parallels Desktop to version 27 on Apple Silicon Macs; for Intel Mac environments, no patch exists — assess whether Parallels can be removed or access restricted, as any local user process can escalate to root. No exploitation signals yet, but the permanent exposure on Intel hardware raises urgency for affected fleets.
  • SOC/IR — Skip
  • Leader — Learn: Intel Mac users running Parallels Desktop have a local-privilege-escalation flaw with no available fix; worth flagging to the engineering manager if your developer fleet still includes Intel Macs, but no board-level action is warranted absent active exploitation.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.