Vendor
Deskin versions through 3.3.4.3 contain an authentication vulnerability in the com.deskin.service.installer XPC service that allows local attackers to execute arbitrary installer packages as root.