<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Endpoint Security for MacOS (Prior to 8.1.300.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/endpoint-security-for-macos-prior-to-8.1.300.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 24 Jul 2026 13:24:29 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/endpoint-security-for-macos-prior-to-8.1.300.0/feed.xml" rel="self" type="application/rss+xml"/><item><title>Multiple Privilege Escalation Vulnerabilities in ESET macOS Products</title><link>https://feed.craftedsignal.io/briefs/2026-07-eset-macos-privesc/</link><pubDate>Fri, 24 Jul 2026 13:24:29 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-eset-macos-privesc/</guid><description>Multiple vulnerabilities discovered in ESET Cyber Security and Endpoint Security for macOS allow an attacker to achieve privilege escalation on affected systems, posing a significant risk to macOS users.</description><content:encoded><![CDATA[<p>CERT-FR has issued an advisory regarding multiple privilege escalation vulnerabilities affecting ESET Cyber Security and Endpoint Security products on macOS. These vulnerabilities, identified as CVE-2026-10610 and CVE-2026-7483, could allow a local attacker to elevate their privileges on an affected system. The vulnerabilities impact various versions of ESET's macOS security solutions, specifically Cyber Security for macOS versions prior to 9.0.6300.0, Endpoint Security for macOS 9.0.x prior to 9.0.6400.0, Endpoint Security for macOS 9.1.x prior to 9.1.3100.0, and Endpoint Security for macOS prior to 8.1.300.0. While the specific exploitation details are not public, the nature of privilege escalation vulnerabilities means that an attacker who has already gained initial access to a system could leverage these flaws to gain higher-level control, bypassing security controls provided by ESET.</p>
<h2 id="impact">Impact</h2>
<p>A successful exploitation of these vulnerabilities would result in an attacker achieving elevated privileges, potentially gaining root or administrative access on the compromised macOS system. This level of access allows an attacker to perform a wide range of malicious activities, including installing persistent malware, modifying critical system configurations, exfiltrating sensitive data, or completely disabling security software. While no specific victim numbers or targeted sectors are mentioned, any organization or individual utilizing the affected ESET products on macOS is at risk. The primary impact is the bypass of intended security boundaries and the potential for complete system compromise.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Refer to ESET's security bulletins for patches, specifically bulletins <code>ca8974</code> and <code>ca8977</code>, and apply the updates immediately to address <code>CVE-2026-10610</code> and <code>CVE-2026-7483</code>.</li>
<li>Ensure ESET Cyber Security for macOS is updated to version 9.0.6300.0 or later.</li>
<li>Ensure ESET Endpoint Security for macOS 9.0.x is updated to version 9.0.6400.0 or later.</li>
<li>Ensure ESET Endpoint Security for macOS 9.1.x is updated to version 9.1.3100.0 or later.</li>
<li>Ensure ESET Endpoint Security for macOS is updated to version 8.1.300.0 or later.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>privilege-escalation</category><category>vulnerability</category><category>macos</category></item></channel></rss>