Parallels Desktop Bug Hands Root to Any Mac User, and Older Macs Can't Get the Patch

A flaw in Parallels Desktop for Mac lets a normal user seize full control of the machine. The fix ships only in Parallels Desktop 27, which won't install on Intel-based Macs.

ThreatVectr Newsdesk· Editor: Lee Brown· 4 min read
cybersecurity defenders responding to a critical alert
Share

Key points

  • JFrog disclosed a local privilege escalation flaw in Parallels Desktop for Mac this week, allowing any standard user account to gain root, the top level of access on a Mac.
  • The bug requires code already running on the Mac as an ordinary user, so it can't be triggered remotely over the internet.
  • Parallels has fixed the flaw in Parallels Desktop 27, released for Apple Silicon Macs only.
  • Intel-based Macs cannot install version 27, leaving those users without an official patch.
  • The research was led by Yuval Moravchick of JFrog's security team.

A popular tool that lets Mac owners run Windows on their machine has a serious hole in it. Security researchers at JFrog say Parallels Desktop for Mac contains a flaw that hands any regular user account full administrator control.

That top level of access is called root. A program running as root can read any file, alter any setting, and install software without restriction. A normal user isn't supposed to get there without a password.

The finding was first reported by The Hacker News.

How does the attack actually work?

An attacker needs to already be running some code on the Mac as an ordinary user. From that starting point, the Parallels bug lets them jump to root. It won't work from across the internet.

This is a second-stage weapon. A criminal first has to get a foothold, perhaps through a booby-trapped download or a phishing email, where scammers trick you into opening a bad file. Once they've got that toehold, Parallels gives them the keys to the whole machine.

Security people call this class of bug local privilege escalation. It's a familiar shape. Think of a burglar who has climbed through a window into the hallway, then finds the safe key sitting on the sideboard.

Worth noting: on 2 September we reported that a JFrog vulnerability turned up in CISA's Known Exploited Vulnerabilities catalog, which tells you this firm's research tends to land on real targets.

Who found it?

Yuval Moravchick, who leads security research at JFrog, is credited with the discovery. JFrog published details this week.

Is there a fix?

Yes, but only for some Macs. Parallels has patched the flaw in Parallels Desktop 27, the newest version of the software.

Here's the catch. Parallels Desktop 27 runs only on Apple Silicon Macs, the newer models with Apple's own M-series chips. Older Intel-based Macs can't install it. Those users are stuck on earlier versions that still carry the bug.

Detail Value
Product affected Parallels Desktop for Mac
Type of flaw Local privilege escalation to root
Fixed in Parallels Desktop 27
Macs that can install the fix Apple Silicon only
Macs left without a fix Intel-based Macs
Credited researcher Yuval Moravchick, JFrog

Should ordinary Mac users worry?

If you run Parallels Desktop on an Apple Silicon Mac, update to version 27. That's the whole job.

If you run it on an older Intel Mac, the situation is uglier. There's no official patched version you can install. Be careful about what you download and open, since this bug only bites after something malicious is already running on your machine. Keep macOS itself up to date, and think hard about whether you still need Parallels on that older hardware.

My read: leaving an entire hardware generation without a patch for a root-level bug is a rough call, even if Parallels has commercial reasons for drawing the line at Apple Silicon. Intel Mac owners paid for the software too. Expect pressure on Parallels to either backport the fix or say clearly that Intel support is over.

Common questions

Can someone hack my Mac over the internet using this bug?

No. The flaw only works if malicious code is already running on your Mac as a normal user. It's a way to make a small break-in much worse, not a way to get in from outside.

What is root and why does it matter?

Root is the highest level of access on a Mac. A program running as root can read or change any file, install anything it likes, and see everything on the machine. That's why handing root to a regular user is a big deal.

© 2026 Threat Vectr