<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Deskin (&lt;= 3.3.4.3) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/deskin--3.3.4.3/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 22:15:30 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/deskin--3.3.4.3/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Local Privilege Escalation in Deskin macOS Installer Service</title><link>https://feed.craftedsignal.io/briefs/2026-10-deskin-priv-esc/</link><pubDate>Thu, 08 Oct 2026 22:15:30 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-deskin-priv-esc/</guid><description>Deskin versions through 3.3.4.3 contain an authentication vulnerability in the com.deskin.service.installer XPC service that allows local attackers to execute arbitrary installer packages as root.</description><content:encoded><![CDATA[<p>Deskin versions 3.3.4.3 and earlier contain a critical local privilege escalation vulnerability within the 'com.deskin.service.installer' XPC service on macOS. The XPC service fails to properly authenticate requests, allowing unprivileged local users to interact with the service directly. An attacker can leverage this misconfiguration to invoke the privileged installer method, which executes installer packages with root-level permissions. Because the service is owned by the root user and performs no credential validation, an attacker can supply a malicious installer package to gain full system control. This vulnerability poses a significant risk to macOS environments where Deskin is installed, as it allows standard users to bypass system security restrictions and escalate to root privileges without requiring existing administrative access.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-11318 results in a full root compromise of the affected macOS host. This allows attackers to install persistent backdoors, access sensitive data across the file system, and disable security controls. This vulnerability affects all Deskin deployments through version 3.3.4.3.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor for unauthorized execution of installer processes originating from the Deskin service.</li>
<li>Review internal software update policies for Deskin and ensure systems are transitioned to a version beyond 3.3.4.3 once a patch is confirmed available by the vendor.</li>
<li>Audit local user activity on macOS endpoints for suspicious calls to XPC services identified as root-owned.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>