Junglewise Threat Intelligence

CVE-2026-11970: Forcepoint One Endpoint Safari Extension privilege escalation on macOS

CVE-2026-11970 · Severity: info · Published 2026-08-13

Executive brief

Forcepoint One Endpoint (F1E) is an endpoint protection and data loss prevention (DLP) solution deployed on corporate macOS devices to prevent sensitive data exfiltration. A non-administrative user can disable the Safari browser extension component that enforces DLP policies, allowing the user to bypass data protection controls and exfiltrate sensitive information without detection or restriction.

Technical details

This vulnerability is an improper check for unusual or exceptional conditions in the Forcepoint One Endpoint Safari Extension on macOS. A local non-admin user can disable the Safari extension, which is responsible for enforcing data loss prevention (DLP) policies, thereby circumventing protection mechanisms designed to prevent data exfiltration. The attack requires local access to the macOS system and interaction with the Safari extension settings. An attacker can achieve complete bypass of DLP controls in Safari, enabling data theft. The vulnerability affects F1E macOS versions before v26.04.5758, and patches are available in the referenced version.

Affected products

  • Forcepoint One Endpoint macOS before 26.04.5758

Timeline

  • 2026-08-13: disclosed

References