Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.installer XPC service that allows local unprivileged attackers to execute arbitrary installer packages as root by connecting to the root-owned service without authentication. Attackers can invoke the privileged installer method to run an attacker-supplied installer, achieving full root compromise of the macOS host.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.installer XPC service that allows local unprivileged attackers to execute arbitrary installer packages as root by connecting to the root-owned service without authentication. Attackers can invoke the privileged installer method to run an attacker-supplied installer, achieving full root compromise of the macOS host. | |
| Title | Deskin 3.3.4.3 XPC Service Privilege Escalation via Unauthenticated Installer | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-08T21:08:29.598Z
Reserved: 2026-06-04T19:52:59.225Z
Link: CVE-2026-11318
No data.
Status : Deferred
Published: 2026-10-08T21:17:53.377
Modified: 2026-10-08T21:35:53.890
Link: CVE-2026-11318
No data.
OpenCVE Enrichment
Updated: 2026-10-08T22:30:18Z
Weaknesses