SECURITY·중요도 8·2026. 09. 16.·The Hacker News
Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
── KO ──────────────────
Parallels Desktop의 취약점이 비관리자 Mac 사용자에게 루트 권한 부여.
Parallels Desktop for Mac에서 발견된 취약점은 일반 로컬 계정이 루트 권한으로 코드를 실행할 수 있도록 한다. 이 공격은 이미 일반 사용자로서 실행 중인 코드가 필요하며, 네트워크를 통해서는 작동하지 않는다. JFrog는 이 취약점을 수정한 Parallels Desktop 27 버전이 있지만, Intel Mac에서는 설치할 수 없다고 밝혔다.
── EN ──────────────────
A flaw in Parallels Desktop allows non-admin Mac users to gain root access.
A vulnerability in Parallels Desktop for Mac allows an ordinary local account to run code as root, the highest level of access on a Mac. The attack requires code already running on the machine as a normal user and does not work over the network. JFrog reported that the fix is included in Parallels Desktop 27, but this version cannot be installed on Intel Macs.