Skip to content
High-Risk Privilege Escalation Vulnerability in DeskIn for macOS

High-Risk Privilege Escalation Vulnerability in DeskIn for macOS

First seen 9 Oct 2026, 01:37 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 02:37 UTC
  • •CVE-2026-11318 allows local privilege escalation on macOS via DeskIn.
  • •The vulnerability affects versions up to 3.3.4.3 and has a CVSS score of 8.5.
  • •No patch is available yet; users should monitor affected systems closely.

A Local Privilege Escalation (LPE) vulnerability, CVE-2026-11318, has been identified in the DeskIn macOS client. This flaw allows unprivileged local users to escalate privileges to root by exploiting the com.deskin.service.installer XPC service, which lacks proper client validation. Attackers can invoke the privileged installer method without authentication, leading to full control of the macOS host. The vulnerability affects versions of DeskIn up to 3.3.4.3, and a proof-of-concept (PoC) was made public on October 1, 2026. As of the latest reports, no patch has been released, and the risk is classified as high due to the potential for data theft and system disruption. Users are advised to restrict local access and monitor for suspicious activity until a fix is available.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-01
Public PoC released
A proof-of-concept for CVE-2026-11318 was made publicly available, demonstrating the exploit method.
github.com
2026-10-08
CVE-2026-11318 published
CVE-2026-11318 was officially published, detailing the local privilege escalation vulnerability in DeskIn.
Redpacketsecurity

More articles in this cluster (3)

Following this threat?

Track CVE-2026-11318 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of DeskIn are affected?
The vulnerability affects DeskIn versions up to 3.3.4.3.
Is there a patch available for this vulnerability?
No, as of now, the vendor has not released a patch for CVE-2026-11318.
What immediate actions should I take?
Restrict local access to affected Macs and monitor for any suspicious installer activity.