Executive brief
Acronis True Image is a backup and data protection suite for macOS. A security flaw in how the software handles system environment variables allows a local user with limited permissions to gain full administrative control over the computer. This could lead to unauthorized access to sensitive files, system-wide data loss, or the installation of malicious software.
Technical details
A local privilege escalation vulnerability exists in Acronis True Image for macOS due to improper handling of environment variables (CWE-15). An attacker with low-privileged local access can manipulate environment variables to influence the execution of the application, potentially leading to the execution of arbitrary code with elevated privileges. The vulnerability affects Acronis True Image OEM (macOS) before build 42571 and Acronis True Image (macOS) before build 42902. Users are advised to update to the latest builds to mitigate this risk.
Affected products
- Acronis True Image OEM (macOS) before build 42571
- Acronis True Image (macOS) before build 42902
Timeline
- 2026-04-10: disclosed
- 2026-04-10: advisory