Critical macOS CUPS Vulnerability (CVE-2026-39875) Exploited via Public PoC
A proof-of-concept (PoC) exploit has been released for CVE-2026-39875, a high-severity macOS vulnerability in the Common UNIX Printing System (CUPS) that enables local privilege escalation via arbitrary file writes with root privileges. The flaw affects macOS Sonoma, Sequoia, and Tahoe versions prior to 14.8.8, 15.7.8, and 26.6, respectively.
Discovered by security researcher Dallas Dubs, the exploit chains two logic flaws in the privileged cupsd daemon. An unprivileged local attacker can register a malicious printer, steal a valid CUPS authentication token during probing, and replay it to create a second printer with a file:// device URI targeting an attacker-controlled path bypassing System Integrity Protection (SIP).
The attack culminates in submitting a print job with controlled data, which cupsd writes to the specified location as root. The PoC, available on GitHub, confirms root-owned file creation but does not directly provide a full interactive shell. However, arbitrary file writes can facilitate privilege escalation by modifying sensitive files (e.g., configurations, scheduled tasks, or application support files), depending on system defenses.
The exploit requires no user interaction and has been demonstrated on macOS Tahoe 26.4.1, Sequoia 15.7.5, and Sonoma 14.8.5. While the impact varies based on SIP restrictions and endpoint security controls, the vulnerability poses a significant risk to shared Mac systems, developer endpoints, and environments where untrusted local code execution is possible.
Apple has patched the flaw in the latest macOS updates (26.6, 15.7.8, and 14.8.8). Security teams are advised to monitor for unusual printer registrations, suspicious print jobs targeting file-based destinations, and unexpected changes to printer device URIs as potential indicators of exploitation. The public PoC increases the likelihood of active testing and attacks, underscoring the urgency of patch deployment.
Source: https://cybersecuritynews.com/public-poc-released-for-cups-vulnerability/
Apple TPRM report: https://www.rankiteo.com/company/appledeveloper
"id": "app1785853507",
"linkid": "appledeveloper",
"type": "Vulnerability",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Users of macOS Sonoma, Sequoia, '
'and Tahoe versions prior to '
'14.8.8, 15.7.8, and 26.6',
'industry': 'Technology',
'location': 'Global',
'name': 'Apple',
'type': 'Technology Company'}],
'attack_vector': 'Local',
'description': 'A proof-of-concept (PoC) exploit has been released for '
'CVE-2026-39875, a high-severity macOS vulnerability in the '
'Common UNIX Printing System (CUPS) that enables local '
'privilege escalation via arbitrary file writes with root '
'privileges. The flaw affects macOS Sonoma, Sequoia, and Tahoe '
'versions prior to 14.8.8, 15.7.8, and 26.6, respectively. The '
'exploit chains two logic flaws in the privileged `cupsd` '
'daemon, allowing an unprivileged local attacker to register a '
'malicious printer, steal a valid CUPS authentication token, '
'and replay it to create a second printer with a `file://` '
'device URI targeting an attacker-controlled path, bypassing '
'System Integrity Protection (SIP). The attack culminates in '
'submitting a print job with controlled data, which `cupsd` '
'writes to the specified location as root.',
'impact': {'operational_impact': 'Privilege escalation enabling unauthorized '
'root access',
'systems_affected': 'macOS Sonoma, Sequoia, and Tahoe versions '
'prior to 14.8.8, 15.7.8, and 26.6'},
'post_incident_analysis': {'corrective_actions': 'Apple patched the '
'vulnerability in macOS '
'updates 26.6, 15.7.8, and '
'14.8.8',
'root_causes': 'Logic flaws in the privileged '
'`cupsd` daemon allowing arbitrary '
'file writes with root privileges'},
'recommendations': 'Deploy macOS updates 26.6, 15.7.8, or 14.8.8 immediately. '
'Monitor for indicators of exploitation such as unusual '
'printer registrations or suspicious print jobs.',
'references': [{'source': 'GitHub (PoC Exploit)'}],
'response': {'containment_measures': 'Apple released patches in macOS updates '
'26.6, 15.7.8, and 14.8.8',
'enhanced_monitoring': 'Monitor for unusual printer '
'registrations, suspicious print jobs '
'targeting file-based destinations, and '
'unexpected changes to printer device '
'URIs',
'remediation_measures': 'Apply macOS updates 26.6, 15.7.8, or '
'14.8.8'},
'title': 'Critical macOS CUPS Vulnerability (CVE-2026-39875) Exploited via '
'Public PoC',
'type': 'Local Privilege Escalation',
'vulnerability_exploited': 'CVE-2026-39875'}