Key Facts
JFrog disclosed CVE-2026-90894, dubbed ParaShells, affecting Parallels Desktop 26.4.0 build 57513 on Apple Silicon Macs. Its researchers demonstrated root code execution from a low-privileged local account.
Technical Details
JFrog attributes the chain to a world-writable prl_disp_service socket, weak local-client authentication, and argument injection in appliance extraction. A running virtual machine is not required for the demonstrated path.
Impact & Mitigation
Upgrade to Parallels Desktop 27.0.0 or later. Until patched, restrict local access and check whether /var/run/prl_disp_service.socket is world-writable, as described in JFrog’s detection guidance.
