logo

IPVanish VPN for macOS Flaw Enables Privilege Escalation and Code Execution

ID: 2d57a023-0541-5e7e-b53d-1b108fe1f8cd

STIX ID: report--2d57a023-0541-5e7e-b53d-1b108fe1f8cd

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-04

Date Updated: 2026-04-22

Author: Divya

...
...

A high-severity privilege escalation (CVE-PENDING, CVSS 8.8) in the IPVanish macOS VPN helper allows local unprivileged processes to gain root by connecting to an unauthenticated XPC listener and exploiting a logic flaw that skips code-signature checks for non-executable files; an attacker can place a malicious script in a world-writable location, have the helper copy it into a privileged folder, make it executable, and run it (via OpenVPNPath or the --up hook). The report describes the vulnerable components, attack flow, exploitation paths, and prescribes mitigations: strict XPC caller authentication, unconditional signature verification, and strict path whitelisting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.