This security flaw impacts macOS versions prior to version 26.6, identified as CVE-2026-43783 with a CVSS score of 7.8, specifically within the DesktopServicesHelper daemon. This flaw allows an untrusted application to bypass operating system access controls and grant arbitrary file ownership changes, ultimately escalating privileges directly to root via Pluggable Authentication Modules. The vulnerability resides in the daemon's failure to verify security entitlements for sandboxed callers executing specific administrative tasks, such as RepairPermissionsForCloudItems, and its inability to sanitize target file paths from incoming XPC dictionaries. Attackers can exploit this weakness by sending an XPC request targeting sensitive system directories, granting them ownership of all enclosed files, which they can then use to create a PAM configuration file allowing automatic password acceptance. This critical flaw poses a severe threat to desktop environments with over 100 million Mac devices running modern macOS installations worldwide, and users should update their systems to version 26.6 or later without delay to prevent unauthorized root account access.
We recommend you to update Apple macOS to version 26.6.[/subscribe_to_unlock_form]
This security flaw impacts macOS versions prior to version 26.6, identified as CVE-2026-43783 with a CVSS score of 7.8, specifically within the DesktopServicesHelper daemon. This flaw allows an untrusted application to bypass operating system access controls and grant arbitrary file ownership changes, ultimately escalating privileges directly to root via Pluggable Authentication Modules. The vulnerability resides in the daemon's failure to verify security entitlements for sandboxed callers executing specific administrative tasks, such as RepairPermissionsForCloudItems, and its inability to sanitize target file paths from incoming XPC dictionaries. Attackers can exploit this weakness by sending an XPC request targeting sensitive system directories, granting them ownership of all enclosed files, which they can then use to create a PAM configuration file allowing automatic password acceptance. This critical flaw poses a severe threat to desktop environments with over 100 million Mac devices running modern macOS installations worldwide, and users should update their systems to version 26.6 or later without delay to prevent unauthorized root account access.
We recommend you to update Apple macOS to version 26.6.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]