PoC public Parallels Desktop for Mac privilege-escalation Parallels mobile
Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
CVE Tools coverage
A public PoC for CVE-2026-90894 shows how a non-admin local user can gain root privileges on a Mac running vulnerable Parallels Desktop for Mac. The flaw abuses appliance extraction to inject tar options through the root-run prl_disp_service, affecting builds below Parallels Desktop 27.0.0. JFrog identifies version 27.0.0 as fixed, but Intel Macs cannot install the 27.x line and may remain without a confirmed fix on Parallels Desktop 26.