CVE-2026-78236

Summary

An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as an Apple-signed process.

Affected Software

VendorProductVersion RangeStatus
Admin By Request (ABR)Admin By Request (ABR)5.2.2 and belowaffected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References