Ghostwire

CVE-2026-11318: Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.installer XPC service...

HIGH CVSS 0.0 EPSS 0.19% Exploit Available 1 PoC

Published: October 8, 2026 | Last Modified: October 8, 2026

Description

Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.installer XPC service that allows local unprivileged attackers to execute arbitrary installer packages as root by connecting to the root-owned service without authentication. Attackers can invoke the privileged installer method to run an attacker-supplied installer, achieving full root compromise of the macOS host.

Ghostwire Analysis — What This Means Practically

Exploitation Probability (EPSS): Low — 0.19% (8th percentile)

Low exploitation probability based on current threat landscape data. Standard patching timeline is appropriate.

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Proof-of-Concept Exploits (1)

Security Coverage (1 articles)

References