


Perceptive Security
SOC/SIEM Consultancy

An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version 1.16.0 upd…
Published:
27 May 2026 at 22:00:00
Alert date:
28 May 2026 at 19:09:38
Source:
nvd.nist.gov
Operating Systems, Cloud & Virtualization
CVE-2026-49237 affects Canonical Multipass for macOS versions before 1.16.3 due to an incomplete fix for CVE-2025-5199. The vulnerability allows local privilege escalation through user-writable auxiliary binaries (multipass, qemu-img, qemu-system-aarch64, qemu-system-x86_64, and sshfs_server) in /Library/Application Support/com.canonical.multipass/bin/. While the main multipassd daemon binary was fixed to use root:wheel ownership, these five co-located binaries retain user ownership and remain writable. The root LaunchDaemon prioritizes this user-writable directory in PATH and calls these binaries by name, allowing attackers to replace them with malicious wrappers. When the root daemon triggers these binaries during normal operations, the malicious code executes with root privileges.
Technical details
Mitigation steps:
Affected products:
Canonical Multipass
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-49237
https://github.com/canonical/multipass/security/advisories/GHSA-r2xg-x32f-23c5
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
