Executive brief
A vulnerability in ESET security software for macOS could allow a person with limited access to a computer to gain full administrative control. By exploiting a flaw in how the software communicates between internal processes, an attacker can create malicious system files that grant them root-level permissions. This could lead to a complete compromise of the affected machine, including the ability to bypass security controls and access sensitive data.
Technical details
A local privilege escalation vulnerability exists in ESET security applications for macOS due to improper privilege management (CWE-269) in the XPC (cross-process communication) service. The service, which runs with root permissions, fails to properly authenticate connections from unprivileged local users. An attacker can exploit this by sending crafted messages to the XPC service to write arbitrary files to the disk, such as a malicious .plist file in the LaunchDaemon folder. This allows the attacker to achieve arbitrary code execution as root upon the next system reboot. ESET has released patches for Endpoint Security and Cyber Security products to address this flaw.
Affected products
- ESET ESET Endpoint Security for macOS 8.0.7200.0 and earlier, 8.1.200.0 and earlier, 9.0.5400.0 and earlier, 9.1.2500.0 and earlier
- ESET ESET Cyber Security for macOS 9.0.5300.0 and earlier
Timeline
- 2026-07-24: disclosed
- 2026-07-24: patched
- 2026-07-24: advisory