Cyber Resilience
← All news
Corroborated

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)

Our takeParallels Desktop CVE-2026-90894 lets any local Mac user escalate to root. Update to version 27 if you run it yourself; Intel users cannot and remain exposed.
Sources (4)
What this means for you — Security leader:Update Parallels Desktop to version 27 on all Intel and Apple Silicon Macs you manage. The flaw lets any local account escalate to root; the patch is unavailable for Intel systems.
What this means for you — Lean IT orgs:If you run Parallels Desktop on any Mac, update it to version 27 right away. The bug lets any normal user on the machine become root; Intel Macs cannot get the fix.
What this means for you — MSP:Check every client Mac running Parallels Desktop and upgrade to version 27 where possible. The local-to-root flaw cannot be patched on Intel hardware, so note those systems.
What this means for you — Researcher:Review and test the ParaShells PoC on your macOS research systems. The CVE-2026-90894 flaw is corroborated and the patch is unavailable for Intel Macs.