PoC Exploit Released for macOS CUPS Root Privilege Escalation Flaw
ID: 24d11350-5229-5716-93d9-34d4e19cd6ea
STIX ID: report--24d11350-5229-5716-93d9-34d4e19cd6ea
Feed Name: Cyber Press
A public proof-of-concept for CVE-2026-39875 demonstrates a macOS CUPS local privilege-escalation that allows an unprivileged local user to obtain a forwarded local authentication token and exploit a timing flaw to cause cupsd to write attacker-controlled data as root. The flaw affects macOS Tahoe, Sequoia, and Sonoma releases prior to macOS 26.6, 15.7.8, and 14.8.8 respectively; organizations are advised to apply Apple’s patches and review local printer registrations and unexpected file:// device URIs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
