ESET Customer Advisory 2026-0013
July 24, 2026
Severity: High
Summary
A report of a local privilege escalation was submitted to ESET by Martin Orem of Binary House. The vulnerability potentially allowed an attacker to write an arbitrary file with fully controlled content as a privileged user. ESET mitigated this by preparing fixed versions of the affected applications.
Details
On systems with the affected ESET applications installed, it was possible for an unprivileged local user to write arbitrary files to the disk. This was achieved through ESET’s XPC (cross-process communication) service, which has root permissions and would accept connections from any user without authentication. An attacker could exploit this to write an arbitrary .plist file to the LaunchDaemon folder and, thus, achieve root code execution upon the next system relaunch.
The reserved CVE ID for this vulnerability is CVE-2026-7483, the CVSS v4.0 score is 8.5, with the following vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
To the best of our knowledge, no exploits targeting this vulnerability exist in the wild.
Solution
ESET prepared fixed builds of the affected applications and recommends upgrading to these or scheduling the upgrades in the near future. The fixed builds are available to download from www.eset.com or via the ESET Repository.
-
ESET Endpoint Security for macOS
- version 9.1.3100.0 and later from the 9.1 version family
- version 9.0.6400.0 and later from the 9.0 version family
- version 8.1.300.0 and later from the 8.1 version family
-
ESET Cyber Security for macOS
- version 9.0.6300.0 and later
Affected applications
-
ESET Endpoint Security for macOS
- version 9.1.2500.0 and earlier from the 9.1 version family
- version 9.0.5400.0 and earlier from the 9.0 version family
- version 8.1.200.0 and earlier from the 8.1 version family
- version 8.0.7200.0 and earlier
-
ESET Cyber Security for macOS
- version 9.0.5300.0 and earlier
Feedback & Support
If you have feedback or questions about this issue, please contact us using the ESET Security Forum or via local ESET Technical Support.
Acknowledgement
ESET values the principles of coordinated disclosure within the security industry and would like to express our thanks to Martin Orem of Binary House.
Version log
Version 1.0 (July 24, 2026): Initial version of this document