High-Risk Privilege Escalation Vulnerability in DeskIn for macOS
Article Content
- •CVE-2026-11318 allows local privilege escalation on macOS via DeskIn.
- •The vulnerability affects versions up to 3.3.4.3 and has a CVSS score of 8.5.
- •No patch is available yet; users should monitor affected systems closely.
A Local Privilege Escalation (LPE) vulnerability, CVE-2026-11318, has been identified in the DeskIn macOS client. This flaw allows unprivileged local users to escalate privileges to root by exploiting the com.deskin.service.installer XPC service, which lacks proper client validation. Attackers can invoke the privileged installer method without authentication, leading to full control of the macOS host. The vulnerability affects versions of DeskIn up to 3.3.4.3, and a proof-of-concept (PoC) was made public on October 1, 2026. As of the latest reports, no patch has been released, and the risk is classified as high due to the potential for data theft and system disruption. Users are advised to restrict local access and monitor for suspicious activity until a fix is available.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-11318 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of DeskIn are affected?
Is there a patch available for this vulnerability?
What immediate actions should I take?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…