<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Parallels - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/parallels/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 10:10:22 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/parallels/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Local Privilege Escalation in Parallels Desktop via Argument Injection</title><link>https://feed.craftedsignal.io/briefs/2026-09-parallels-pe/</link><pubDate>Mon, 28 Sep 2026 10:10:22 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-parallels-pe/</guid><description>Parallels Desktop versions prior to 27.0.0 are vulnerable to local privilege escalation via an argument injection flaw in the root-privileged prl_disp_service.</description><content:encoded><![CDATA[<p>Parallels Desktop for macOS versions prior to 27.0.0 contain a critical local privilege escalation (LPE) vulnerability tracked as CVE-2026-90894. The flaw exists within the 'prl_disp_service', a background service running with root privileges that exposes a world-writable socket to local users. An attacker can interact with this socket to trigger an appliance installation process.</p>
<p>The service implements an insecure re-tokenization mechanism when executing 'tar' or 'bsdtar' for archive extraction. By providing a malicious archive name containing additional tar flags, an attacker can perform argument injection. This allows the execution of arbitrary commands as root, most notably through the '--use-compress-program' flag, which can point to an attacker-controlled file residing in a user-writable directory like /tmp. Successful exploitation grants the attacker full root access to the host system.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker establishes local access on the target macOS host as a standard user.</li>
<li>Attacker interacts with the world-writable IPC socket exposed by 'prl_disp_service'.</li>
<li>Attacker sends a malformed request to the service to trigger the appliance installation routine.</li>
<li>The service constructs a command string incorporating an attacker-provided archive folder name.</li>
<li>The attacker-supplied name injects malicious arguments, specifically '--use-compress-program', into the command string.</li>
<li>'prl_disp_service' executes 'tar' or 'bsdtar' with the injected flags running as root.</li>
<li>'tar' spawns the specified external program defined in the injected argument, executing it with root privileges.</li>
<li>Attacker gains full root control over the system.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-90894 allows any local unprivileged user on a macOS system to elevate privileges to root. This impacts all Parallels Desktop installations on macOS prior to version 27.0.0. The ability to execute arbitrary code as root provides an attacker with complete control over the host, enabling data exfiltration, installation of persistence mechanisms, and bypassing of macOS security controls.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Parallels Desktop to version 27.0.0 or later immediately to address CVE-2026-90894.</li>
<li>For hosts that cannot be upgraded, restrict local login access as an interim control, as the dispatcher socket is reachable by any local account.</li>
<li>Deploy the provided detection logic to identify 'prl_disp_service' spawning 'tar' or 'bsdtar' with an anomalous number of arguments.</li>
<li>Investigate any child processes spawned by 'tar' or 'bsdtar' that originate from 'prl_disp_service', especially those referencing paths in /tmp or /var/tmp.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>privilege-escalation</category><category>macos</category><category>vulnerability</category><category>cve-2026-90894</category></item></channel></rss>