惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
B
Blog
Stack Overflow Blog
Stack Overflow Blog
量子位
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
T
Tailwind CSS Blog
MongoDB | Blog
MongoDB | Blog
小众软件
小众软件
博客园 - 三生石上(FineUI控件)
Recent Announcements
Recent Announcements
U
Unit 42
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
腾讯CDC
D
DataBreaches.Net
Microsoft Azure Blog
Microsoft Azure Blog
G
Google Developers Blog
M
MIT News - Artificial intelligence
P
Proofpoint News Feed
罗磊的独立博客
L
LangChain Blog
V
Visual Studio Blog
雷峰网
雷峰网
aimingoo的专栏
aimingoo的专栏
宝玉的分享
宝玉的分享

Security Affairs

Carding service Jerry’s Store leak exposes 345,000 stolen payment cards Anthropic launches Claude Security to counter rapid AI-Powered exploits SonicWall patches three SonicOS flaws in Gen 6, 7 and 8 firewalls. Patch them now Copy Fail: New Linux bug enables Root via page‑cache corruption Agent’s claims on WhatsApp access spark security concerns Meta accused of violating DSA by failing to safeguard minors Large-scale Roblox hacking operation shut down by Ukrainian authorities CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure Internet censorship index reveals Russia’s lead and widespread content blocking All supported cPanel versions hit by critical auth bug, now patched U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog ShinyHunters exploit Anodot incident to target Vimeo CVE-2026-3854 GitHub flaw enables remote code execution Signal Phishing Campaign Targets German Officials in Suspected Russian Operation Microsoft fixes Entra ID flaw enabling privilege escalation New Android spyware Morpheus linked to Italian surveillance firm NCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort links Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software LINKEDIN BROWSERGATE Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting Fast16: Pre-Stuxnet malware that targeted precision engineering software Italy moves to extradite Chinese national to the U.S. over hacking charges U.S. utility giant Itron discloses a security breach Critical bug in CrowdStrike LogScale let attackers access files GopherWhisper: new China-linked APT targets Mongolia with Go-based malware SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94 Trigona ransomware adopts custom tool to steal data and evade detection Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITION U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog
Broadcom releases VMware Fusion security update for root ...
Pierluigi Pa · 2026-05-14 · via Security Affairs

Broadcom patched a high-severity VMware Fusion flaw, CVE-2026-41702, that could let local attackers gain root privileges.

Broadcom released a security update for VMware Fusion to address a high-severity vulnerability, tracked as CVE-2026-41702, that could allow local attackers to escalate privileges to root on affected systems.

The flaw is a time-of-check time-of-use (TOCTOU) vulnerability affecting operations performed by a SETUID binary that was reported by security researcher Mathieu Farrell.

Broadcom explained that an attacker with local non-administrative user privileges can exploit the bug to escalate privileges to root on the system where Fusion is installed.

“A local privilege escalation vulnerability in VMware Fusion was privately reported to Broadcom.” reads the advisory. “Updates are available to remediate this vulnerability in affected Broadcom products.”

Successful exploitation could allow attackers with limited access to gain full control of vulnerable machines, significantly increasing the risk posed by compromised user accounts or insider threats.

TOCTOU vulnerabilities occur when a system checks the state of a resource and later uses it without ensuring that the state has not changed in the meantime. Attackers can exploit this timing gap to manipulate files, permissions, or other resources and execute unauthorized actions with elevated privileges.

VMware Fusion is widely used by developers, IT professionals, and security researchers to run virtual machines on macOS systems. Because the vulnerability requires local access, it does not expose systems directly to remote compromise. However, privilege escalation flaws remain highly valuable to attackers because they can turn a limited foothold into complete system compromise.

The patch arrives as Broadcom participates in the Pwn2Own hacking competition taking place this week in Berlin. The event, organized by Trend Micro’s Zero Day Initiative, brings together some of the world’s top security researchers to demonstrate zero-day exploits targeting widely used enterprise and consumer technologies.

VMware products have historically attracted strong interest from Pwn2Own participants due to the high value of virtualization exploits. This year, participants are expected to showcase attacks against VMware ESX, with successful demonstrations potentially earning rewards of up to $200,000.

Interestingly, VMware Workstation, which has frequently appeared as a target in previous Pwn2Own editions and generated significant payouts for researchers, was removed from this year’s list of eligible targets.

Organizations and users running VMware Fusion are advised to apply the latest updates as soon as possible to reduce the risk of privilege escalation attacks.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, VMware Fusion)