A critical security vulnerability (CVE-2026-18577) was identified in macOS, allowing local privilege escalation from an unprivileged user to root without user interaction or password prompts. The flaw was caused by a composition error between system components, specifically 'DesktopServicesHelper' and 'securityd'. Apple patched this vulnerability in macOS 26.6, but it was previously exploitable in versions prior to this update (validated on 26.5.2).
Despite the existence of a public proof-of-concept exploit, no in-the-wild exploitation has been reported. Immediate updates to the latest version are recommended for users.