Official company update
ParaShells: Parallels Desktop Turns Appliance Install Into a Root Shell
JFrog·jfrog.com·
What the source says
Your Mac runs a vulnerable version of Parallels Desktop. A malicious package, compromised CI job, or other unprivileged process is already running on it. No admin access. No Parallels-signed client. One appliance-install request later, attacker-controlled code runs as root. While testing Desktop 26.4.0 (build 57513) on Apple silicon, we found that an unprivi
Checking access…
The original publication, including any images and updates, remains with the publisher.
Checking free source access…
More about JFrog
Official · jfrog.comThe Year the Vulnerability Backlog Changed ShapeOfficial · jfrog.comThe New Rules of Patching: When a Fix Becomes a Blueprint for AttackersOfficial · jfrog.comJFrog Artifactory Supports LuaRocks Hosting for NGINX, OpenResty and KongOfficial · jfrog.comExtending the Single Source of Truth to the Agentic Software Supply Chain