logo

macOS CUPS Flaw Lets Local Attackers Write Arbitrary Files as Root

ID: 2de72ec2-3657-5f03-af59-1c5183d11654

STIX ID: report--2de72ec2-3657-5f03-af59-1c5183d11654

Feed Name: GBHackers

Threat Score
55/100

Date Published: 2026-08-04

Date Updated: 2026-08-04

Author: Divya

...
...

A CUPS privilege vulnerability (CVE-2026-39875) in macOS Sonoma, Sequoia, and Tahoe allows a local attacker to register a malicious printer and combine token capture with a timing race to cause cupsd to write attacker-controlled content as root to arbitrary (non-SIP-protected) locations; a public PoC exists and Apple has released updates—organizations should patch, restrict local access, and monitor unexpected printer registrations and root-owned files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.