Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-39875-macOS-CUPS-LPE — Unprivileged user to root on macOS Sonoma, Sequoia, and Tahoe. Patched in macOS 26.6 / 15.7.8 / 14.8.8. | Kitploit
Tools/GitHubGitHub/mac-123456789-lab/cve-2026-39875-macos-cups-lpe
Privilege EscalationExploitationBinary Exploitation
GitHubmac-123456789-lab/cve-2026-39875-macos-cups-lpe

CVE-2026-39875-macOS-CUPS-LPE

Unprivileged user to root on macOS Sonoma, Sequoia, and Tahoe. Patched in macOS 26.6 / 15.7.8 / 14.8.8.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
10223 days agoNot yet reviewed

CVE-2026-39875-macOS-CUPS-LPE

Unprivileged user to root via CUPS vulnerability affecting macOS Tahoe, Sequoia, and Sonoma prior to macOS 26.6 / 15.7.8 / 14.8.8.

Proof of Concept Demonstrations

macOS Tahoe 26.4.1

Tahoe 26.4.1

macOS Sequoia 15.7.5

Sequoia 15.7.5

macOS Sonoma 14.8.5

Sonoma 14.8.5

Root Cause

The vulnerability arises from two chained logic flaws in the privileged cupsd daemon.

1. Privileged authentication token forwarded across a trust boundary.

When CUPS probes a newly registered printer, it forwards a valid Local authentication token to the printer's backend — the endpoint specified by the printer's device-uri. Because an unprivileged user controls that device-uri, they can register a printer pointing at a listener they control and receive a token that was never intended to leave the trusted subsystem boundary. The design assumes the backend is trusted; allowing unprivileged users to register printers breaks that assumption.

2. Root-privileged file I/O reachable before authentication validation completes.

Within a reliably reproducible timing window during printer registration, cupsd performs a file write with root privileges before authentication validation has completed. The privileged I/O is not gated on the auth check resolving, and both the destination path and file contents are attacker-influenced at the point the write occurs.


Demonstration

root@kitploit:~
python3 poc.py

The proof of concept chains the two flaws in three stages.

Stage 1 — Token capture. The attacker registers a printer whose device-uri points at a local listener they control, then triggers a probe. cupsd forwards a valid Local authentication token to the attacker-controlled listener.

Stage 2 — Token replay. The attacker replays the captured token to register a second printer with a file:// device-uri targeting an arbitrary, non-SIP-protected path of their choosing.

Stage 3 — Arbitrary write as root. The attacker submits a print job with attacker-controlled content to the second printer. cupsd writes the job data to the specified path as root. No user interaction is required at any stage

Afterwards, the script will verify the file was created as root, thus demonstrating the vulnerability.

Note: This proof-of-concept demonstrates arbitrary file write as root only. It does not escalate privileges.

Credits

Independently discovered by Dallas Dubs; also credited by Apple are Aaron Grattafiori - NVIDIA AI Red Team, XBreach.ai, Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs

Download Tool