logo

Three HP Easy Start Flaws Let Attackers Gain Root Privileges on macOS

ID: cae874cc-9b24-57bc-a545-855ca8d5e908

STIX ID: report--cae874cc-9b24-57bc-a545-855ca8d5e908

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-09-03

Date Updated: 2026-09-11

Author: Divya

...
...

Three high-severity vulnerabilities were discovered in HP Easy Start for macOS affecting the uninstaller's predictable temporary-file usage (allowing privileged file modification via symlink), an unmaintained embedded OSPFTP download component that can fall back to FTP (exposing package downloads), and an App Transport Security configuration that permits cleartext HTTP. Combined, these issues could allow local unprivileged users to cause root-owned file corruption or denial-of-service and could enable network-positioned attackers to intercept or manipulate installer packages under fallback conditions; HP patched the issues in HP Easy Start 2.16.7.260722 and recommends updating and removing outdated installers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.