Skip to content
Threat Feed
high advisory

Local Privilege Escalation in Deskin macOS Installer Service

Deskin versions through 3.3.4.3 contain an authentication vulnerability in the com.deskin.service.installer XPC service that allows local attackers to execute arbitrary installer packages as root.

CVE search metadata

CVE search record: CVE-2026-11318. Severity: high. CVSS: 7.8. KEV: no. Product: Deskin (<= 3.3.4.3). Brief: Local Privilege Escalation in Deskin macOS Installer Service. Brief link: https://feed.craftedsignal.io/briefs/2026-10-deskin-priv-esc/

Deskin versions 3.3.4.3 and earlier contain a critical local privilege escalation vulnerability within the 'com.deskin.service.installer' XPC service on macOS. The XPC service fails to properly authenticate requests, allowing unprivileged local users to interact with the service directly. An attacker can leverage this misconfiguration to invoke the privileged installer method, which executes installer packages with root-level permissions. Because the service is owned by the root user and performs no credential validation, an attacker can supply a malicious installer package to gain full system control. This vulnerability poses a significant risk to macOS environments where Deskin is installed, as it allows standard users to bypass system security restrictions and escalate to root privileges without requiring existing administrative access.

Impact

Successful exploitation of CVE-2026-11318 results in a full root compromise of the affected macOS host. This allows attackers to install persistent backdoors, access sensitive data across the file system, and disable security controls. This vulnerability affects all Deskin deployments through version 3.3.4.3.

Recommendation

  • Monitor for unauthorized execution of installer processes originating from the Deskin service.
  • Review internal software update policies for Deskin and ensure systems are transitioned to a version beyond 3.3.4.3 once a patch is confirmed available by the vendor.
  • Audit local user activity on macOS endpoints for suspicious calls to XPC services identified as root-owned.

Immediate actions

Review local macOS endpoints for the presence of Deskin version 3.3.4.3 or earlier.

IT Operations 24h

Mitigations

Upgrade Deskin to the latest available version beyond 3.3.4.3 to remediate CVE-2026-11318.

immediate IT Operations

CVE-2026-11318