Local Privilege Escalation in Intego Personal Backup for macOS
CVE-2026-26225
8.5HIGH
What is CVE-2026-26225?
Intego Personal Backup, a macOS utility designed for scheduled backups and system cloning, contains a vulnerability that allows local privilege escalation. This flaw arises from the improper handling of backup task definitions, which are stored in a directory accessible to non-privileged users. If exploited via a crafted malicious serialized task file, attackers can trigger arbitrary file writes to sensitive system areas, ultimately enabling them to gain elevated privileges, including root access.
Affected Version(s)
Personal Backup MacOS 0 <= 10.9.0
References
CVSS V4
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Mathieu Farrell of Quarkslab
