HomeSecurityVMware Fusion: Vulnerability allows privilege escalation

VMware Fusion: Vulnerability allows privilege escalation

A new serious vulnerability in VMware Fusion has caused widespread concern in the cybersecurity community, as it allows local users with limited privileges to gain full root access to affected macOS systems. The issue affects Broadcom's popular software, which is widely used by developers, enterprises, and IT professionals to create and manage virtual machines on Mac computers.

VMware Fusion

The vulnerability is tracked as CVE-2026-41702 and according to security advisory VMSA-2026-0003, it was officially patched on May 14, 2026. However, experts warn that any system that continues to use older versions of VMware Fusion remains exposed to an immediate risk of privilege escalation attacks.

The most worrying aspect is that there are no temporary mitigations or alternative protection solutions. The only effective defense is to immediately install the security update.

See also: Pwn2Own Berlin 2026 – Day 1: Researchers hacked Windows 11 and Edge

What is the TOCTOU vulnerability and why is it considered dangerous?

The new vulnerability is based on a TOCTOU flaw , or “Time-of-Check Time-of-Use.” This is one of the most well-known and dangerous classes of race condition vulnerabilities, where an attacker exploits the time gap between the system checking a resource and the moment that resource is actually used.

In the case of VMware Fusion, the flaw was found in SETUID binary . SETUID binaries are special executable files on Unix and Linux systems that temporarily operate with elevated privileges, even when run by regular users.

This means that a malicious user can intervene in the short time “window” between control and use of a resource, introducing malicious changes and gaining root access.

Attacks of this type are considered particularly serious because they transform a low-privilege account into full control of the operating system.

VMware Fusion: Vulnerability allows privilege escalation

Which users are affected?

Broadcom confirmed that the vulnerability affects those using VMware Fusion 25H2 on macOS. The attack does not require remote access or an administrator account. A local account with basic user rights. This means that even limited access to a system can lead to a complete compromise of the computer.

See also: CVE-2026-42897: Active Exchange Server vulnerability exploit

This scenario is considered particularly dangerous in corporate environments, shared Mac workstations, and development systems where multiple users have access to the same equipment.

At the same time, experts warn that the vulnerability could also be exploited by malware already running on the system with limited privileges. In such a case, a simple malicious process could turn into a full-blown breach without requiring any additional interaction from the user.

Why VMware Fusion is an attractive target

VMware Fusion is widely used in software development environments, infrastructure testing, cybersecurity labs, and corporate macOS ecosystems. The ability to create multiple virtual machines makes it an essential tool for developers and IT administrators.

This very characteristic, however, also makes it a particularly attractive target for cybercriminals. A successful privilege escalation exploit in virtualization software can provide access not only to the host system but also to wider corporate infrastructure.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: New YellowKey vulnerability bypasses BitLocker

In recent years, attacks against virtualization platforms have been on the rise, as organizations increasingly rely on virtualized environments for cloud applications, testing, and containerized workloads.

VMware Fusion: Vulnerability allows privilege escalation

Broadcom's response and security recommendations

Broadcom credited researcher Mathieu Farrell , also known as @coiffeur0x90, for responsibly disclosing the vulnerability via a private report. The company has released the VMware Fusion 26H1 patch , which includes a full patch for CVE-2026-41702.

Security teams are now urged to immediately identify all affected endpoints and expedite the upgrade process without delay.

The lack of a workaround means that any unpatched system remains essentially open to a potential root escalation attack. In environments where VMware Fusion is used for software development or access to sensitive corporate infrastructure, the risk is considered particularly high.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS