Back to News
Cybersecurity

Critical Vulnerability in Parallels Desktop Exposes Mac Users to Root Access Exploit

A security flaw in Parallels Desktop for Mac permits non-admin users to gain root access, while Intel Macs lack the necessary update.

A recent report from JFrog has revealed a significant vulnerability in Parallels Desktop for Mac that allows non-admin local accounts to execute code with root privileges. This flaw poses a serious security risk, as it can potentially enable attackers to manipulate system settings and access sensitive data, but it requires that the malicious code is already running on the machine, limiting its scope to local exploitation rather than remote attacks. Notably, the fix is embedded in Parallels Desktop version 27, which unfortunately cannot be installed on Intel Macs, leaving a segment of users vulnerable.

For businesses utilizing Parallels Desktop, this vulnerability underscores the critical importance of promptly updating software to mitigate potential security risks. Organizations should evaluate their reliance on Parallels Desktop, particularly within their security protocols, and consider implementing additional safeguards for systems that cannot receive the update. The inability of Intel Macs to patch this flaw raises concerns about the broader implications of software updates across varying hardware, emphasizing the need for comprehensive cybersecurity strategies that account for such discrepancies to protect against local attacks and ensure the integrity of sensitive information.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/09/parallels-desktop-flaw-lets-non-admin.html)*