CVE-2026-20610
macOS vulnerability analysis and mitigation

Overview

CVE-2026-20610 is a symlink-following vulnerability in the Setup Assistant component of Apple macOS Tahoe that allows a local application to gain root privileges. The vulnerability was disclosed on February 11, 2026, as part of Apple's security advisory for macOS Tahoe 26.3, and affects macOS Tahoe versions prior to 26.3. It was discovered by Gergely Kalman (@gergely_kalman) and carries a CVSS v3.1 base score of 7.8 (High) (Apple Advisory).

Technical details

The vulnerability is classified as CWE-59 (Improper Link Resolution Before File Access / 'Link Following'), meaning the Setup Assistant component fails to properly validate symbolic links before performing privileged file operations. An attacker with a low-privileged local account can craft a malicious symlink that redirects a privileged file operation performed by Setup Assistant, ultimately achieving root-level code execution. No user interaction is required beyond running the malicious application. Apple addressed the issue with improved handling of symlinks (Apple Advisory).

Impact

Successful exploitation allows a local application to escalate privileges to root on the affected macOS system, resulting in high confidentiality, integrity, and availability impact. An attacker achieving root access can read any file on the system, modify or delete critical system files, install persistent malware, and potentially pivot to other systems or services accessible from the compromised host (Apple Advisory).

Exploitation steps

  1. Gain local access: Obtain a low-privileged user account or deploy a malicious application on the target macOS Tahoe system running a version prior to 26.3.
  2. Identify the vulnerable operation: Determine the specific file path that Setup Assistant accesses with elevated (root) privileges during its execution.
  3. Create a malicious symlink: Replace or pre-create a file or directory at the expected path with a symbolic link pointing to a sensitive or privileged target location (e.g., /etc/sudoers, a root-owned binary, or a system configuration file).
  4. Trigger Setup Assistant: Execute or wait for Setup Assistant to perform its privileged file operation, which follows the attacker-controlled symlink without proper validation.
  5. Achieve root privileges: The privileged operation is redirected through the symlink to the attacker's chosen target, enabling arbitrary file writes or reads as root, which can be leveraged to install a backdoor, modify sudoers, or otherwise establish persistent root access (Apple Advisory).

Indicators of compromise

  • File System: Unexpected symbolic links in directories accessed by Setup Assistant (e.g., /var/folders/, /tmp/, or user-writable paths); newly created or modified files in root-owned directories (e.g., /etc/, /usr/local/) with unusual timestamps.
  • Logs: Unified system log entries showing Setup Assistant (/System/Library/CoreServices/Setup Assistant.app) accessing unexpected file paths or encountering symlink resolution; sudo or privilege escalation events not initiated by a legitimate user session.
  • Process: Unusual child processes spawned with root privileges from Setup Assistant or related processes; unexpected modifications to /etc/sudoers or root crontabs.
  • Network: Outbound connections from newly created root-level processes to unknown external IP addresses, potentially indicating post-exploitation activity (Apple Advisory).

Mitigation and workarounds

Apple has patched this vulnerability in macOS Tahoe 26.3, released February 11, 2026. Users should update to macOS Tahoe 26.3 or later immediately. No configuration-based workaround is available; upgrading is the only remediation. Organizations should prioritize patching macOS endpoints and consider restricting the installation of untrusted third-party applications as a defense-in-depth measure (Apple Advisory).

Community reactions

The vulnerability was noted in the SANS Internet Storm Center diary shortly after disclosure, and was tracked by VulDB and security aggregators such as CCN-CERT. Community discussion was limited, consistent with the moderate severity and local-only attack vector. No major vendor statements beyond Apple's advisory or notable researcher commentary beyond the discoverer credit (Gergely Kalman) have been identified (Apple Advisory).

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management