CVE Tools
Back to feed
PoC public Parallels Desktop for Mac privilege-escalation Parallels mobile

Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix

The Hacker News·By The Hacker News··6 min read
CVE Tools coverage

A public PoC for CVE-2026-90894 shows how a non-admin local user can gain root privileges on a Mac running vulnerable Parallels Desktop for Mac. The flaw abuses appliance extraction to inject tar options through the root-run prl_disp_service, affecting builds below Parallels Desktop 27.0.0. JFrog identifies version 27.0.0 as fixed, but Intel Macs cannot install the 27.x line and may remain without a confirmed fix on Parallels Desktop 26.