Junglewise Threat Intelligence

CVE-2026-2638: X-VPN macOS privilege escalation in quarantine workflow

CVE-2026-2638 · Severity: info · CVSS 7.3 · Published 2026-06-09

Executive brief

A security vulnerability exists in the macOS version of X-VPN downloaded directly from the vendor's website. This flaw allows a person with physical or local access to the computer to manipulate the software's file-handling process to corrupt or modify system files they shouldn't have access to. If exploited, this could allow a standard user to gain administrative control over the device, potentially leading to full system compromise or data loss.

Technical details

The vulnerability (CVE-2026-2638) is a Time-of-Check Time-of-Use (TOCTOU) race condition within the quarantine and restore workflow of X-VPN for macOS. A local attacker with low-level privileges can use symlink manipulation during this workflow to redirect file operations to sensitive system files. This allows the attacker to achieve privileged file corruption or local privilege escalation (LPE). The issue specifically affects the standalone version downloaded from the X-VPN website (versions 77.0 through 77.5) and has been patched in version 77.5.1.

Affected products

  • X-VPN X-VPN macOS (Website Version) 77.0 - 77.5

Timeline

  • 2026-06-07: patched: Fix released in version 77.5.1
  • 2026-06-09: disclosed: Public disclosure by Fluid Attacks and NVD publication

References