Parallels Desktop for Mac users should be aware of a newly discovered security vulnerability that permits non-administrative accounts to execute code with root access. This flaw was identified by JFrog, a software company specializing in vulnerability research, and is present in versions of Parallels Desktop that Intel Mac users cannot update to fix.
Understanding the Security Flaw
This vulnerability, designated as CVE-2026-90894 by JFrog, involves a service within Parallels Desktop that runs with root privileges. Named ParaShells, the flaw allows any application on the Mac to connect to a service socket that is improperly secured. The attack is executed locally and does not require network access, making it reliant on code already running on the machine.
JFrog’s research indicates that the vulnerability affects the Mac host itself rather than the virtual machines running Windows or Linux. The flaw is linked to a service that processes virtual machine installation commands, which can be manipulated to execute arbitrary code as root, due to inadequate input validation.
Impact and Fix for Apple Silicon Macs
The vulnerability is addressed in Parallels Desktop 27, which is only compatible with Macs featuring Apple silicon chips. This version, according to JFrog, has been updated to prevent the exploit by securing the service socket and modifying how installation commands are processed. However, Intel Mac users are unable to install this update due to compatibility restrictions.
Parallels has confirmed that version 27.0.0 and subsequent updates, such as 27.0.1, incorporate the necessary changes to protect against the vulnerability. Despite this, Parallels has not issued an official statement regarding the specific CVE or detailed the changes in their security documentation.
Challenges for Intel Mac Users
For those using Intel-based Macs, the situation is more complex. Parallels Desktop 26 remains the latest version available, and JFrog has indicated that this version does not include the security fix, leaving Intel users potentially vulnerable. Parallels has stated that support for Intel Macs will continue, but there is no confirmation whether the fix will be backported to version 26.
Intel users are advised to remain on version 26, as Parallels continues to provide maintenance updates. However, these updates have not addressed the specific vulnerability, and users should exercise caution by limiting local access to machines and monitoring their systems for any unauthorized access.
Recommendations and Future Outlook
Administrators should ensure that only authorized personnel have local access to machines running Parallels Desktop, especially those that cannot be updated to the fixed version. It is also crucial to verify which version is installed and whether the vulnerability is present using specific commands provided by JFrog.
Looking ahead, the resolution of this issue for Intel Macs remains uncertain. Users are encouraged to stay informed about updates from Parallels and to consider alternative measures to bolster their security posture until a comprehensive fix is available for all affected systems.
