{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/deskin/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:deskin:deskin:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-11318"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Deskin (\u003c= 3.3.4.3)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Deskin"],"content_html":"\u003cp\u003eDeskin versions 3.3.4.3 and earlier contain a critical local privilege escalation vulnerability within the 'com.deskin.service.installer' XPC service on macOS. The XPC service fails to properly authenticate requests, allowing unprivileged local users to interact with the service directly. An attacker can leverage this misconfiguration to invoke the privileged installer method, which executes installer packages with root-level permissions. Because the service is owned by the root user and performs no credential validation, an attacker can supply a malicious installer package to gain full system control. This vulnerability poses a significant risk to macOS environments where Deskin is installed, as it allows standard users to bypass system security restrictions and escalate to root privileges without requiring existing administrative access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-11318 results in a full root compromise of the affected macOS host. This allows attackers to install persistent backdoors, access sensitive data across the file system, and disable security controls. This vulnerability affects all Deskin deployments through version 3.3.4.3.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor for unauthorized execution of installer processes originating from the Deskin service.\u003c/li\u003e\n\u003cli\u003eReview internal software update policies for Deskin and ensure systems are transitioned to a version beyond 3.3.4.3 once a patch is confirmed available by the vendor.\u003c/li\u003e\n\u003cli\u003eAudit local user activity on macOS endpoints for suspicious calls to XPC services identified as root-owned.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T22:15:30Z","date_published":"2026-10-08T22:15:30Z","id":"https://feed.craftedsignal.io/briefs/2026-10-deskin-priv-esc/","summary":"Deskin versions through 3.3.4.3 contain an authentication vulnerability in the com.deskin.service.installer XPC service that allows local attackers to execute arbitrary installer packages as root.","title":"Local Privilege Escalation in Deskin macOS Installer Service","url":"https://feed.craftedsignal.io/briefs/2026-10-deskin-priv-esc/"}],"language":"en","title":"CraftedSignal Threat Feed - Deskin","version":"https://jsonfeed.org/version/1.1"}