{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/cyber-security-for-macos-prior-to-9.0.6300.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-10610"},{"id":"CVE-2026-7483"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Cyber Security for macOS (prior to 9.0.6300.0)","Endpoint Security for macOS 9.0.x (prior to 9.0.6400.0)","Endpoint Security for macOS 9.1.x (prior to 9.1.3100.0)","Endpoint Security for macOS (prior to 8.1.300.0)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","vulnerability","macos"],"_cs_type":"advisory","_cs_vendors":["ESET"],"content_html":"\u003cp\u003eCERT-FR has issued an advisory regarding multiple privilege escalation vulnerabilities affecting ESET Cyber Security and Endpoint Security products on macOS. These vulnerabilities, identified as CVE-2026-10610 and CVE-2026-7483, could allow a local attacker to elevate their privileges on an affected system. The vulnerabilities impact various versions of ESET's macOS security solutions, specifically Cyber Security for macOS versions prior to 9.0.6300.0, Endpoint Security for macOS 9.0.x prior to 9.0.6400.0, Endpoint Security for macOS 9.1.x prior to 9.1.3100.0, and Endpoint Security for macOS prior to 8.1.300.0. While the specific exploitation details are not public, the nature of privilege escalation vulnerabilities means that an attacker who has already gained initial access to a system could leverage these flaws to gain higher-level control, bypassing security controls provided by ESET.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eA successful exploitation of these vulnerabilities would result in an attacker achieving elevated privileges, potentially gaining root or administrative access on the compromised macOS system. This level of access allows an attacker to perform a wide range of malicious activities, including installing persistent malware, modifying critical system configurations, exfiltrating sensitive data, or completely disabling security software. While no specific victim numbers or targeted sectors are mentioned, any organization or individual utilizing the affected ESET products on macOS is at risk. The primary impact is the bypass of intended security boundaries and the potential for complete system compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRefer to ESET's security bulletins for patches, specifically bulletins \u003ccode\u003eca8974\u003c/code\u003e and \u003ccode\u003eca8977\u003c/code\u003e, and apply the updates immediately to address \u003ccode\u003eCVE-2026-10610\u003c/code\u003e and \u003ccode\u003eCVE-2026-7483\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eEnsure ESET Cyber Security for macOS is updated to version 9.0.6300.0 or later.\u003c/li\u003e\n\u003cli\u003eEnsure ESET Endpoint Security for macOS 9.0.x is updated to version 9.0.6400.0 or later.\u003c/li\u003e\n\u003cli\u003eEnsure ESET Endpoint Security for macOS 9.1.x is updated to version 9.1.3100.0 or later.\u003c/li\u003e\n\u003cli\u003eEnsure ESET Endpoint Security for macOS is updated to version 8.1.300.0 or later.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-24T13:24:29Z","date_published":"2026-07-24T13:24:29Z","id":"https://feed.craftedsignal.io/briefs/2026-07-eset-macos-privesc/","summary":"Multiple vulnerabilities discovered in ESET Cyber Security and Endpoint Security for macOS allow an attacker to achieve privilege escalation on affected systems, posing a significant risk to macOS users.","title":"Multiple Privilege Escalation Vulnerabilities in ESET macOS Products","url":"https://feed.craftedsignal.io/briefs/2026-07-eset-macos-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - Cyber Security for MacOS (Prior to 9.0.6300.0)","version":"https://jsonfeed.org/version/1.1"}