CVE-2026-2637

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an attacker to gain root access on a Mac by exploiting a flaw in the iBoysoft NTFS software's helper service, which doesn’t require any authentication. To take advantage of this, the attacker must have local access to the machine running the affected version of the software.

Technical Description

iBoysoft NTFS for Mac contains a local privilege escalation vulnerability in its privileged helper daemon ntfshelperd. The daemon exposes an NSConnection service that runs as root without implementing any authentication or authorization checks. This issue affects iBoysoft NTFS: 8.0.0.

CVSS Vector Analysis

Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeChanged

Vector String

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$4,158($1K-$5K)
Vendor Response
Grade APatched in 0 days

Quick Information

Published

Mar 3, 2026

about 1 month ago

Last Modified

Mar 3, 2026

about 1 month ago