Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-11318 — Local Privilege Escalation (LPE) Vulnerabilities in DeskIn macOS Client | Kitploit
Tools/GitHubGitHub/cr0wld3r/cve-2026-11318
Privilege EscalationVulnerability AnalysisExploitation
GitHubcr0wld3r/cve-2026-11318

CVE-2026-11318

Local Privilege Escalation (LPE) Vulnerabilities in DeskIn macOS Client

View Repository
2 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-11318: Local Privilege Escalation in DeskIn macOS Client

Vendor: DeskIn
Product: DeskIn macOS Client
Affected Versions: <= v3.3.4.3

Overview

A Local Privilege Escalation (LPE) vulnerability has been identified in the DeskIn macOS client. This vulnerability allows an unprivileged local user to escalate their privileges to root.

Description

DeskIn installs a daemon named DeskIn_Service which runs as the root user. It exposes a Mach XPC service named com.deskin.service.installer.

The implementation of this XPC endpoint lacks proper client validation. The NSXPCListenerDelegate fails to perform adequate security checks on incoming connections. It does not verify the code signature or entitlements of the connecting client. Consequently, any unprivileged application or local user on the macOS system can connect to this XPC service and invoke the submitInstallerToSystemDomainWithPath: method.

Affected Code Path / Component

  • Component: /Applications/DeskIn.app/Contents/MacOS/DeskIn_Service
  • XPC Mach Service Name: com.deskin.service.installer
  • Vulnerable Method: submitInstallerToSystemDomainWithPath:hostBundleIdentifier:homeDirectory:userName:jobDictionary:completion:

Proof of Concept

https://github.com/user-attachments/assets/46a26c48-3a28-405a-8430-3bc041951261

Mitigation & Recommendations

To secure the XPC service, the shouldAcceptNewConnection: method must explicitly reject unauthorized clients.

Recommendation: Verify the code signature of the connecting process. Ensure that the client is signed by the specific Apple Developer Team ID and possesses a specific entitlement or bundle identifier matching the legitimate DeskIn client.

As the vendor has not released a patch for these issues at the time of publication, users of the DeskIn macOS client are advised to disable the DeskIn_Service if not strictly needed or uninstall the software until a patch is available.


Found by:
Long, Dang Hoang of SACOMBANK

Download Tool