Skip to content
New macOS Flaw Allows Users to Disable Security Tools Without Admin Rights

New macOS Flaw Allows Users to Disable Security Tools Without Admin Rights

First seen 24 Jun 2026, 22:09 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •June 25, 2026 at 21:30 UTC
  • •Standard user accounts can disable enterprise security tools on macOS without admin rights.
  • •The vulnerability exploits macOS's trust validation process, affecting major products like CrowdStrike Falcon.
  • •Kandji has patched the issue, assigning CVE-2026-39118, but the flaw may impact other applications.

Researchers at XM Cyber have identified a macOS vulnerability that enables standard user accounts to disable enterprise security tools without requiring administrator credentials. This technique exploits the way macOS validates application trust, allowing attackers to impersonate trusted components and invoke privileged functions. The flaw affects major security products, including CrowdStrike Falcon and Kandji MDM, and does not require kernel exploits or trigger alerts. XM Cyber's tool, XPC Hunter, will be presented at Black Hat USA in August 2026 to help identify similar vulnerabilities. Kandji has patched the issue and assigned CVE-2026-39118, published on June 15, 2026. The vulnerability poses a significant risk to organizations relying on macOS for security. Apple has yet to respond or publish an advisory regarding this issue.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 91d ago How this analysis works

Timeline

2026-06-15
CVE-2026-39118 published
Kandji assigned CVE-2026-39118 for an access control issue allowing standard users to invoke restricted functionality.
Article 5
2026-06-24
XM Cyber discloses macOS vulnerability
XM Cyber reveals a technique allowing standard users to disable security tools without admin rights, affecting major EDR and MDM solutions.
Article 1
2026-06-24
Kandji patches vulnerability
Kandji has fixed the vulnerability that allows standard users to disable its MDM solution, addressing CVE-2026-39118.
Article 4
2026-06-24
XPC Hunter tool announced
XM Cyber announces the development of XPC Hunter, an open-source tool to identify similar macOS vulnerabilities, to be presented at Black Hat USA in August.
Article 2

More articles in this cluster (12)

Following this threat?

Track ShinyHunters, Apple and CVE-2026-39118 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed