CVE-2026-11318: Deskin 3.3.4.3 XPC Service Privilege Escalation via Unauthenticated Installer
Published Oct 8, 2026
·Updated
Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.installer XPC service that allows local unprivileged attackers to execute arbitrary installer packages as root by connecting to the root-owned service without authentication. Attackers can invoke the privileged installer method to run an attacker-supplied installer, achieving full root compromise of the macOS host.
Affected Software
1 affected component
Deskin Deskin<=3.3.4.3
Event History
Oct 8, 2026
CVE Published
via MITRE·09:08 PM
Data Sourced
via MITRE·09:08 PM
DescriptionSeverityWeakness