
Local Privilege Escalation (LPE) Vulnerabilities in DeskIn macOS Client
Vendor: DeskIn
Product: DeskIn macOS Client
Affected Versions: <= v3.3.4.3
A Local Privilege Escalation (LPE) vulnerability has been identified in the DeskIn macOS client. This vulnerability allows an unprivileged local user to escalate their privileges to root.
DeskIn installs a daemon named DeskIn_Service which runs as the root user. It exposes a Mach XPC service named com.deskin.service.installer.
The implementation of this XPC endpoint lacks proper client validation. The NSXPCListenerDelegate fails to perform adequate security checks on incoming connections. It does not verify the code signature or entitlements of the connecting client. Consequently, any unprivileged application or local user on the macOS system can connect to this XPC service and invoke the submitInstallerToSystemDomainWithPath: method.
/Applications/DeskIn.app/Contents/MacOS/DeskIn_Servicecom.deskin.service.installersubmitInstallerToSystemDomainWithPath:hostBundleIdentifier:homeDirectory:userName:jobDictionary:completion:https://github.com/user-attachments/assets/46a26c48-3a28-405a-8430-3bc041951261
To secure the XPC service, the shouldAcceptNewConnection: method must explicitly reject unauthorized clients.
Recommendation: Verify the code signature of the connecting process. Ensure that the client is signed by the specific Apple Developer Team ID and possesses a specific entitlement or bundle identifier matching the legitimate DeskIn client.
As the vendor has not released a patch for these issues at the time of publication, users of the DeskIn macOS client are advised to disable the DeskIn_Service if not strictly needed or uninstall the software until a patch is available.
Found by:
Long, Dang Hoang of SACOMBANK