Parallels Desktop flaw lets a normal Mac user become root, stranding Intel Macs
Researchers at JFrog disclosed a flaw in Parallels Desktop, which runs Windows and Linux virtual machines on a Mac, that lets a non-administrator user gain root on the Mac itself. Tracked as CVE-2026-90894 and named ParaShells, the issue is that Parallels' root-level background service listens on a socket that was left world-writable, so any program running as a normal user can connect to it and escalate to root. It needs code already running locally, not network access. The fix is in Parallels Desktop 27, but Intel Macs cannot install that version, leaving those users without a patch. Apple-silicon users should update to the latest release on that line.
- Check
- Update Parallels Desktop to 27.0.1 or later on Apple-silicon Macs; on Intel Macs, which cannot install the fix, limit who can run code locally and consider alternatives until a fix is available.
- Affected
- Mac users running Parallels Desktop below version 27 (CVE-2026-90894); a non-admin local user can reach the world-writable service socket to gain root, and Intel Macs cannot install the fixed version.
- Fix
- Patch Apple-silicon Macs to the latest Parallels release, restrict local code execution on Intel Macs that cannot update, monitor for unexpected privilege escalation, and weigh alternative virtualization for unpatchable systems.