SECURITY·중요도 8·2026. 09. 16.·The Hacker News

Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix

── KO ──────────────────

Parallels Desktop의 취약점이 비관리자 Mac 사용자에게 루트 권한 부여.

Parallels Desktop for Mac에서 발견된 취약점은 일반 로컬 계정이 루트 권한으로 코드를 실행할 수 있도록 한다. 이 공격은 이미 일반 사용자로서 실행 중인 코드가 필요하며, 네트워크를 통해서는 작동하지 않는다. JFrog는 이 취약점을 수정한 Parallels Desktop 27 버전이 있지만, Intel Mac에서는 설치할 수 없다고 밝혔다.


── EN ──────────────────

A flaw in Parallels Desktop allows non-admin Mac users to gain root access.

A vulnerability in Parallels Desktop for Mac allows an ordinary local account to run code as root, the highest level of access on a Mac. The attack requires code already running on the machine as a normal user and does not work over the network. JFrog reported that the fix is included in Parallels Desktop 27, but this version cannot be installed on Intel Macs.

원문 보기 →목록으로