Darkreading New macOS Flaw Allows Users to Disable Security Tools Without Admin Rights
Article Content
- •Standard user accounts can disable enterprise security tools on macOS without admin rights.
- •The vulnerability exploits macOS's trust validation process, affecting major products like CrowdStrike Falcon.
- •Kandji has patched the issue, assigning CVE-2026-39118, but the flaw may impact other applications.
Researchers at XM Cyber have identified a macOS vulnerability that enables standard user accounts to disable enterprise security tools without requiring administrator credentials. This technique exploits the way macOS validates application trust, allowing attackers to impersonate trusted components and invoke privileged functions. The flaw affects major security products, including CrowdStrike Falcon and Kandji MDM, and does not require kernel exploits or trigger alerts. XM Cyber's tool, XPC Hunter, will be presented at Black Hat USA in August 2026 to help identify similar vulnerabilities. Kandji has patched the issue and assigned CVE-2026-39118, published on June 15, 2026. The vulnerability poses a significant risk to organizations relying on macOS for security. Apple has yet to respond or publish an advisory regarding this issue.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (12)
Following this threat?
Track ShinyHunters, Apple and CVE-2026-39118 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
AI Infrastructure Under Siege: Session Hijacking and Exploits Surge Recent cybersecurity incidents have targeted AI platforms and enterprise systems, with significant exploits reported. Notable vulnerabilities include the PaperCut remote code execution flaw (CVE-2026-65105) being actively exploited. Attackers are hijacking authenticated browser sessions for AI services like Claude…
FBI Breached via Unpatched Oracle Software Vulnerability The FBI confirmed a breach by the ShinyHunters ransomware group, which exploited a critical vulnerability (CVE-2026-35273) in Oracle's PeopleSoft software. The vulnerability allowed unauthenticated remote code execution, enabling attackers to access sensitive employee data and operational systems. ShinyHunters…