EIP-2026-103369

PRE-CVE

Apple macOS 10.13.1 (High Sierra) - Insecure Cron System Local Privilege Escalation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103369. PoCs published by Mark Wadham.

AI-analyzed exploit summary This writeup describes a privilege escalation vulnerability in macOS where a non-root user can write to any non-SIP-protected file, including cron files, to execute commands as root. The exploit leverages the cron system's lack of ownership validation for crontab files.

Description

Apple macOS 10.13.1 (High Sierra) - Insecure Cron System Local Privilege Escalation

Exploits (1)

exploitdb WRITEUP
by Mark Wadham · localmacos
https://www.exploit-db.com/exploits/43247

This writeup describes a privilege escalation vulnerability in macOS where a non-root user can write to any non-SIP-protected file, including cron files, to execute commands as root. The exploit leverages the cron system's lack of ownership validation for crontab files.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: macOS (version not specified)
Auth required
Prerequisites: Non-root user access · Ability to write to non-SIP-protected files
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026