EIP-2026-103369
PRE-CVEApple macOS 10.13.1 (High Sierra) - Insecure Cron System Local Privilege Escalation
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103369. PoCs published by Mark Wadham.
AI-analyzed exploit summary This writeup describes a privilege escalation vulnerability in macOS where a non-root user can write to any non-SIP-protected file, including cron files, to execute commands as root. The exploit leverages the cron system's lack of ownership validation for crontab files.
Description
Apple macOS 10.13.1 (High Sierra) - Insecure Cron System Local Privilege Escalation
Exploits (1)
This writeup describes a privilege escalation vulnerability in macOS where a non-root user can write to any non-SIP-protected file, including cron files, to execute commands as root. The exploit leverages the cron system's lack of ownership validation for crontab files.