HIGH 8.8 NVD
CVE-2026-78236
An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communicati
An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as an Apple-signed process.
References
- https://docs.adminbyrequest.com/security-advisories/abr-mac-26-01.htm
- https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-110/
This high severity vulnerability with a CVSS score of 8.8 was published on 2026-08-26 via NVD.
vulnfeed aggregates 11364 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.