WARNING--Parallels Desktop CVE-2026-90894 Gives Any Local User Root on a Mac; the Fix Is in Version 27, Which Intel Macs Cannot Install

A Mac screen with one Parallels Desktop window titled Windows 11: inside it a Windows mapping application shows a 3D aerial view of a city's office towers and a domed building under a tab labeled Rooftop Scene, with the Windows 11 taskbar along the bottom of the window, the macOS menu bar across the top of the screen and the macOS Dock below.
Image: Parallels · A Mac screen with one Parallels Desktop window titled Windows 11: inside it a Windows mapping application shows a 3D aerial view of a city's office towers and a domed building under a tab labeled Rooftop Scene, with the Windows 11 taskbar along the bottom of the window, the macOS menu bar across the top of the screen and the macOS Dock below.

Parallels Desktop for Mac has a hole that lets any account on the Mac, administrator or not, run code as root. JFrog's write-up, published September 15 under the name ParaShells, proved it on Parallels Desktop 26.4.0 on an Apple silicon Mac and names 27.0.0 as the fixed version. Version 27 installs only on Apple silicon, so as of October 3 an Intel Mac running Parallels has no build that JFrog calls fixed.

A root service answers any local account

The flaw is CVE-2026-90894. The CVE record, published by JFrog on September 14, scores it 7.8, classes it as argument injection, and carries a CISA assessment of the same day that lists exploitation as "none". Parallels Desktop installs a helper, prl_disp_service, that runs as root and listens on a socket any process on the Mac can open. JFrog's Yuval Moravchick found that its local login accepts an unsigned program run by a non-admin user, and that its appliance installer builds a tar command around a folder name the caller supplies. A quotation mark in that name turns what follows into options for tar, and tar's --use-compress-program option then runs the attacker's script as root. No virtual machine has to be running.

This is not a remote attack: something must already be running on the Mac under an ordinary account. JFrog's examples are a malicious Homebrew formula, "a poisoned npm preinstall, or a browser download that lands as a local user", and one weak student account on a shared lab Mac. It adds: "From root, the attacker can replace system software, read other users' data, and persist via launchd."

Parallels has not named the bug, and the dates disagree

JFrog's timeline has the report going to Parallels on July 14 and the fix arriving "in Parallels Desktop 27.0.0" on September 1. Parallels' release notes for version 27 date 27.0.0 to August 25, 27.0.1 to September 1 and 27.0.2, build 58673, to September 17. The one security line under 27.0.0 covers "the virtual networking stack, virtual GPU command processing, and VirtIO subsystem"; the appliance installer is not in it, and no entry names the CVE. Parallels' list of security fixes says the company "does not disclose, confirm or discuss security vulnerabilities until they are fixed, and the fix has been released to the public"; the page was last reviewed on May 20, 2025, its newest row is a fix shipped on April 17, 2025, and this CVE is not on it. The Hacker News reported the mismatch on September 16; 27.0.2 postdates both dates.

Intel Macs and Macs on Ventura stay on version 26

Parallels' system requirements give version 27 two conditions: an Apple silicon chip and macOS Sonoma 14.7 or newer. On Ventura 13 and earlier the installer sets up an older version, and Parallels' August 25 press release calls 27 "designed exclusively for Apple silicon Macs". The same day, Parallels' note to Intel owners said version 26 "fully supports Intel-based Mac computers" and that they can "expect future security and maintenance updates."

None has come that names this bug. Parallels' release notes for version 26, as read on October 3, end at 26.4.2, build 57518, of September 8, whose only listed change is an Enterprise deployment fix. JFrog's proof was on Apple silicon and it reports no test on an Intel Mac, but JFrog's advisory lists every version below 27.0.0 as affected and says of the old line: "Hosts that stay on the 26.x line, including 26.4.2, do not have that extract change."

Two lines have been patched at once before: our August 2007 note on Virtual PC 6.1.2 and 7.0.3 recorded Microsoft closing the same memory-overwrite hole in versions 6 and 7. The processor news in our October 2004 item on Virtual PC 7 was that it would now run on the G5.

What to do now

JFrog's check is the About box for the version and one Terminal command for the socket, ls -l /var/run/prl_disp_service.socket. If the line it prints begins srwxrwxrwx and the version is "at or near 26.4.0", JFrog says to "assume exposure until you can confirm a patched build."

On an Apple silicon Mac running Sonoma 14.7 or newer, move to Parallels Desktop 27, whose newest build on October 3 was 27.0.2. On an Intel Mac, or a Mac held on Ventura, there was as of October 3 nothing to install; JFrog's advice until there is something is to "restrict local login on those Macs", which at home means no guest or shared accounts and care over what you run.

We have not run JFrog's steps or installed either version. Parallels told Intel owners on August 25 to expect security updates, and this is the first one it owes them. [Macs Only!]

Sources

  1. JFrog, “ParaShells: Parallels Desktop Turns Appliance Install Into a Root Shell” accessed Oct 3, 2026The September 15, 2026 post by Yuval Moravchick, JFrog Vulnerability Research Team Lead: the name ParaShells; an unprivileged local user running code as root through prl_disp_service, proved on Parallels Desktop 26.4.0 (build 57513) on Apple silicon; the root helper and its world-writable socket that any process can connect to; PrlSrv_LoginLocal succeeding for an unsigned client run by a non-admin user; the tar command built around the caller's parent path, the quote break and --use-compress-program running the script as root; no running VM required; the lab proof on macOS arm64 only ("We did not regression-test every older build"); the Homebrew, npm preinstall and browser-download examples and the weak student account on a shared lab Mac; the quotation beginning "From root"; the disclosure timeline (reported to Parallels 2026-07-14, "Fix released in Parallels Desktop 27.0.0" 2026-09-01); 27.0.0 as the fixed version; the version check in the About box, the socket command ls -l /var/run/prl_disp_service.socket with its srwxrwxrwx mode, and the lines "at or near 26.4.0" and "assume exposure until you can confirm a patched build"; accessed October 3, 2026.
  2. JFrog, “Parallels Desktop is vulnerable to a Local Privilege Escalation via Appliance Extract Argument Injection” accessed Oct 3, 2026The advisory for CVE-2026-90894, published 14 Sep, 2026: affected versions "< 27.0.0"; the sentence "Hosts that stay on the 26.x line, including 26.4.2, do not have that extract change."; and the mitigation "Until every host is on 27.0.0 or later, restrict local login on those Macs."; accessed October 3, 2026.
  3. CVE, “CVE-2026-90894: Parallels Desktop local privilege escalation via appliance extract argument injection” accessed Oct 3, 2026The record published 2026-09-14 with JFrog as the assigning CNA; CVSS 3.1 base score 7.8, High; CWE-88 argument injection; and the CISA ADP assessment timestamped 2026-09-14 with Exploitation: none; read through the CVE Services record the page displays, October 3, 2026.
  4. Parallels, “KB Parallels: Parallels Desktop 27 updates summary” accessed Oct 3, 2026The release dates 27.0.0 August 25, 2026, 27.0.1 September 1, 2026 and 27.0.2 (58673) September 17, 2026; the 27.0.0 security line on the virtual networking stack, virtual GPU command processing, and VirtIO subsystem; no entry naming CVE-2026-90894 or the appliance installer; accessed October 3, 2026.
  5. Parallels, “KB Parallels: Parallels Desktop Security Updates” accessed Oct 3, 2026The statement that Parallels does not disclose, confirm or discuss security vulnerabilities until they are fixed, and the fix has been released to the public; the page's Last Review date of May 20, 2025; its newest row, CVE-2024-54189, fixed in 20.3.0 and dated April 17, 2025; and the absence of CVE-2026-90894 from its table; accessed October 3, 2026.
  6. The Hacker News, “Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix” accessed Oct 3, 2026The September 16, 2026 report by Swati Khandelwal that JFrog's September 1 date for the fix does not match Parallels' release notes, and accessed October 3, 2026.
  7. Parallels, “KB Parallels: Parallels Desktop for Mac System Requirements” accessed Oct 3, 2026Parallels Desktop 27 requiring an Apple silicon chip and macOS Sonoma 14.7 or newer, and the footnote that on earlier macOS versions, including Ventura 13, the installer sets up an earlier supported product version; accessed October 3, 2026.
  8. Parallels, “Parallels Desktop 27 Expands Professional Windows App Support with Faster Graphics and AI Acceleration” accessed Oct 3, 2026The August 25, 2026 press release: Parallels Desktop 27 "is designed exclusively for Apple silicon Macs"; and the press image of ArcGIS Pro in a Windows 11 virtual machine; accessed October 3, 2026.
  9. Parallels, “KB Parallels: Parallels Desktop compatibility with Intel-based Mac computers” accessed Oct 3, 2026The page last reviewed August 25, 2026: Parallels Desktop 26 "fully supports Intel-based Mac computers" and Intel owners can keep using it and "expect future security and maintenance updates"; accessed October 3, 2026.
  10. Parallels, “KB Parallels: Parallels Desktop 26 updates summary” accessed Oct 3, 2026As read on October 3, 2026: 26.4.2 (57518), released September 8, 2026, as the newest build of version 26, with one listed change, an Enterprise Edition declarative deployment fix.
Saw something? Send a tip or a correction

The archive ran on reader tips. What did you see, where, and do you want the credit? Something wrong on this page? Say so and it gets fixed.

Read by the editor. You get a copy by email. Never published without your say.

More in Security · This month in the archive