Local Privilege Escalation in Intego Personal Backup for macOS
CVE-2026-26225

8.5HIGH

Key Information:

Vendor

Intego

Vendor
CVE Published:
12 February 2026

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2026-26225?

Intego Personal Backup, a macOS utility designed for scheduled backups and system cloning, contains a vulnerability that allows local privilege escalation. This flaw arises from the improper handling of backup task definitions, which are stored in a directory accessible to non-privileged users. If exploited via a crafted malicious serialized task file, attackers can trigger arbitrary file writes to sensitive system areas, ultimately enabling them to gain elevated privileges, including root access.

Affected Version(s)

Personal Backup MacOS 0 <= 10.9.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mathieu Farrell of Quarkslab
.