A critical local privilege escalation vulnerability in Parallels Desktop for Mac could allow a non-administrator user or unprivileged process to execute attacker-controlled code with root privileges This article explores vulnerability parallels desktop. . This issue, tracked as CVE-2026-90894, is known as “ParaShells.” The vulnerability was discovered in Parallels Desktop 26.4.0 build 57513 on Apple Silicon Macs.
The attack targets prl_disp_service, a privileged host daemon used by Parallels Desktop to perform sensitive operations, such as managing virtual machines, configuring networking, and installing appliance packages. The combined vulnerabilities include three key issues: a world-writable Unix socket, weak local client authentication, and argument injection during appliance extraction. The PrlSrv_LoginLocal function reportedly accepts connections based on operating system peer credentials, bypassing the need to verify that Parallels signed the client.
The LPE attack chain (Source: Jfrog) During appliance installation, the service generates a tar extraction command using attacker-supplied path values. By placing a quotation mark inside the parent path, an attacker can terminate the expected quoted value and inject an additional tar option. Potential attack vectors include malicious software, compromised CI jobs, poisoned npm scripts, Homebrew formulas, and other code running as a standard user.
Successful exploitation would enable attackers to access files, modify system software, install persistent daemons, alter sudo configurations, and gain full control over the affected Mac. Reduce SOC alert investigation time by 21 minutes.











.webp?w=1600&fit=1600,900&ssl=1)