


Perceptive Security
SOC/SIEM Consultancy

An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version 1.16.0 upd…
Published:
27 mei 2026 om 22:00:00
Alert date:
28 mei 2026 om 15:02:45
Source:
nvd.nist.gov
Operating Systems, Cloud & Virtualization
CVE-2026-49237 affects Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the multipassd daemon binary ownership was updated to root:wheel in version 1.16.0, five auxiliary binaries (multipass, qemu-img, qemu-system-aarch64, qemu-system-x86_64, and sshfs_server) in /Library/Application Support/com.canonical.multipass/bin/ remain user-writable. The root LaunchDaemon configures a PATH that prioritizes this user-writable directory and invokes binaries by bare names. A local attacker can replace auxiliary binaries with malicious wrappers, causing malicious code to execute with root privileges when the daemon triggers them during routine operations like 'multipass launch', resulting in local privilege escalation.
Technical details
Mitigation steps:
Affected products:
Canonical Multipass for macOS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-49237
https://github.com/canonical/multipass/security/advisories/GHSA-r2xg-x32f-23c5
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
