top of page
perceptive_background_267k.jpg

An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version 1.16.0 upd…

Published:

27 May 2026 at 22:00:00

Alert date:

28 May 2026 at 19:09:38

Source:

nvd.nist.gov

Click to open the original link from this advisory

Operating Systems, Cloud & Virtualization

CVE-2026-49237 affects Canonical Multipass for macOS versions before 1.16.3 due to an incomplete fix for CVE-2025-5199. The vulnerability allows local privilege escalation through user-writable auxiliary binaries (multipass, qemu-img, qemu-system-aarch64, qemu-system-x86_64, and sshfs_server) in /Library/Application Support/com.canonical.multipass/bin/. While the main multipassd daemon binary was fixed to use root:wheel ownership, these five co-located binaries retain user ownership and remain writable. The root LaunchDaemon prioritizes this user-writable directory in PATH and calls these binaries by name, allowing attackers to replace them with malicious wrappers. When the root daemon triggers these binaries during normal operations, the malicious code executes with root privileges.

Technical details

Mitigation steps:

Affected products:

Canonical Multipass

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page