Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-78236 1 Admin By Request (abr) 1 Admin By Request (abr) 2026-08-28 8.8 High
An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as an Apple-signed process.
CVE-2026-78237 1 Admin By Request (abr) 1 Admin By Request (abr) 2026-08-28 7.8 High
Insufficient input validation in ABR allows a low-privileged user to inject malicious entries into the sudoers file, resulting in persistent root access that remained effective after the ABR session ended.