Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can’t Install Fix
AI-summarised brief · reviewed before publication
Parallels Desktop for Mac contains a flaw that lets a non‑administrator local account execute code as root on Apple‑silicon Macs. The vulnerability, dubbed ParaShells and tracked as CVE‑2026‑90894, exploits a world‑writable socket in the background service prl_disp_service, allowing an attacker to inject tar options that run arbitrary programs with root privileges. The fix is included in Parallels Desktop 27, which only supports Apple‑silicon Macs, leaving Intel Mac users unable to install the patch. The flaw requires local code execution and does not affect virtual machines.
💡 Why It Matters
- · The issue exposes a critical privilege‑escalation path on a widely used virtualization platform, potentially allowing malware to gain full control of a Mac without administrative rights.
- · It underscores the need for vendors to maintain patch availability across all supported hardware.