CVE-2026-11318
Deskin 3.3.4.3 XPC Service Privilege Escalation via Unauthenticated Installer
- Published
- Oct 8, 2026
- Updated
- Oct 8, 2026
- Assigning CNA
- VulnCheck
- Evidence observed
- Oct 3, 2026
Primary CVSS
cvelist · CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NSummary
Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.installer XPC service that allows local unprivileged attackers to execute arbitrary installer packages as root by connecting to the root-owned service without authentication. Attackers can invoke the privileged installer method to run an attacker-supplied installer, achieving full root compromise of the macOS host.
Sources
Local Privilege Escalation (LPE) Vulnerabilities in DeskIn macOS Client
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.