A proof-of-concept exploit has been released for CVE-2026-39875, a macOS CUPS local privilege-escalation vulnerability that allows an unprivileged user to execute arbitrary file writes while running with root privileges. The vulnerability exists in Apple's implementation of the Common Unix Printing System (CUPS), specifically within the privileged cupsd daemon. It can be triggered without user interaction and relies on chaining two logic flaws during printer registration and print-job handling.

macOS Sequoia 15.7.5 (Source: mac Lab) allows the attacker to submit print jobs, which are written by CUPS as root to the selected filesystem location. Although labeled as a local privilege-escalation flaw, this proof of concept lacks the capability to provide a complete root shell or automatically change the attacker's effective user identity.

Instead, it showcases an arbitrary root file-write primitive, which can be highly significant depending on writable paths, local configurations, and the presence of privileged services that modify attacker-controlled files. Security teams should also review local printer-registration permissions and investigate suspicious CUPS printer entries, particularly those using unexpected local listener addresses or file:// device URIs. Apple also acknowledged Aaron Grattafiori from the NVIDIA AI Red Team, XBreach.ai, and Andreas Jaegersberger and Ro Achterberg of Nosebeard Labs for their contributions.

Utilize ANY.RUN to detect vulnerabilities and prevent breaches, thereby minimizing response costs and reducing business disruptions.