CVE-2026-78236 PUBLISHED

Insecure PIN derivation mechanism in Admin By Request (ABR)

Assigner: CSA
Reserved: 24.08.2026 Published: 26.08.2026 Updated: 26.08.2026

An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as an Apple-signed process.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor Admin By Request (ABR)
Product Admin By Request (ABR)
Versions Default: unaffected
  • Version 5.2.2 and below is affected

Solutions

Users and administrators of affected product versions are advised to update to the latest version promptly.

References