Executive brief
Mullvad VPN is a privacy-focused service that encrypts internet traffic. A security flaw in the macOS installer allows a local user with administrative rights to gain full system (root) control during the installation or upgrade process. This could allow an attacker to bypass security restrictions or compromise the entire operating system.
Technical details
A local privilege escalation vulnerability exists in the Mullvad VPN installer for macOS (versions 2026.1 and below). The installer's preinstall script executes binaries from the '/Applications/Mullvad VPN.app' directory without verifying the authenticity or ownership of the application bundle. A local user in the admin group can exploit this by pre-placing a malicious application bundle at that path before an installation or upgrade occurs. When the installer is run, it executes the attacker-controlled binaries with root privileges. The issue is resolved in version 2026.2-beta1 and later.
Affected products
- Mullvad Mullvad VPN <= 2026.1
Timeline
- 2026-05-08: advisory: Vendor advisory GHSA-c2g6-w5fq-vw3m published
- 2026-05-19: disclosed: CVE-2026-32323 published to NVD