
New Parallels Desktop Flaw Lets Local Users Seize Root Control of Macs
A newly documented security flaw in Parallels Desktop, identified as CVE-2026-90894 and nicknamed "ParaShells," could let any local account on a Mac escalate to full root control of the host machine, according to researchers at JFrog.
The risk is greatest on developer machines, where something as ordinary as a compromised Homebrew formula or a malicious npm preinstall script could serve as the entry point for escalating from a standard user to complete system control.
Shared computers with multiple local accounts — think university labs or office workstations — face similar exposure, said Yuval Moravchick, who leads JFrog's vulnerability research team.
Once an attacker reaches r...