CVE-2026-2637 PUBLISHED

Assigner: Fluid Attacks
Reserved: 17.02.2026 Published: 03.03.2026 Updated: 03.03.2026

iBoysoft NTFS for Mac contains a local privilege escalation vulnerability in its privileged helper daemon ntfshelperd. The daemon exposes an NSConnection service that runs as root without implementing any authentication or authorization checks.

This issue affects iBoysoft NTFS: 8.0.0.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor iBoysoft
Product iBoysoft NTFS
Versions Default: unaffected
  • Version 8.0.0 is affected

Credits

  • Oscar Uribe finder

References

Problem Types

  • CWE-732 Incorrect Permission Assignment for Critical Resource CWE

Impacts

  • CAPEC-233 Privilege Escalation