
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20610 is a symlink-following vulnerability in the Setup Assistant component of Apple macOS Tahoe that allows a local application to gain root privileges. The vulnerability was disclosed on February 11, 2026, as part of Apple's security advisory for macOS Tahoe 26.3, and affects macOS Tahoe versions prior to 26.3. It was discovered by Gergely Kalman (@gergely_kalman) and carries a CVSS v3.1 base score of 7.8 (High) (Apple Advisory).
The vulnerability is classified as CWE-59 (Improper Link Resolution Before File Access / 'Link Following'), meaning the Setup Assistant component fails to properly validate symbolic links before performing privileged file operations. An attacker with a low-privileged local account can craft a malicious symlink that redirects a privileged file operation performed by Setup Assistant, ultimately achieving root-level code execution. No user interaction is required beyond running the malicious application. Apple addressed the issue with improved handling of symlinks (Apple Advisory).
Successful exploitation allows a local application to escalate privileges to root on the affected macOS system, resulting in high confidentiality, integrity, and availability impact. An attacker achieving root access can read any file on the system, modify or delete critical system files, install persistent malware, and potentially pivot to other systems or services accessible from the compromised host (Apple Advisory).
/etc/sudoers, a root-owned binary, or a system configuration file)./var/folders/, /tmp/, or user-writable paths); newly created or modified files in root-owned directories (e.g., /etc/, /usr/local/) with unusual timestamps./System/Library/CoreServices/Setup Assistant.app) accessing unexpected file paths or encountering symlink resolution; sudo or privilege escalation events not initiated by a legitimate user session./etc/sudoers or root crontabs.Apple has patched this vulnerability in macOS Tahoe 26.3, released February 11, 2026. Users should update to macOS Tahoe 26.3 or later immediately. No configuration-based workaround is available; upgrading is the only remediation. Organizations should prioritize patching macOS endpoints and consider restricting the installation of untrusted third-party applications as a defense-in-depth measure (Apple Advisory).
The vulnerability was noted in the SANS Internet Storm Center diary shortly after disclosure, and was tracked by VulDB and security aggregators such as CCN-CERT. Community discussion was limited, consistent with the moderate severity and local-only attack vector. No major vendor statements beyond Apple's advisory or notable researcher commentary beyond the discoverer credit (Gergely Kalman) have been identified (Apple Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."