惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

量子位
F
Fortinet All Blogs
J
Java Code Geeks
Y
Y Combinator Blog
Stack Overflow Blog
Stack Overflow Blog
V
Visual Studio Blog
M
MIT News - Artificial intelligence
腾讯CDC
Last Week in AI
Last Week in AI
The Cloudflare Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Jina AI
Jina AI
Microsoft Security Blog
Microsoft Security Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
P
Proofpoint News Feed
博客园 - 叶小钗
Recent Announcements
Recent Announcements
T
Tailwind CSS Blog
Engineering at Meta
Engineering at Meta
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
人人都是产品经理
人人都是产品经理
L
LangChain Blog
博客园 - 司徒正美
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻

Security Affairs

Agent’s claims on WhatsApp access spark security concerns Meta accused of violating DSA by failing to safeguard minors Large-scale Roblox hacking operation shut down by Ukrainian authorities CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure Internet censorship index reveals Russia’s lead and widespread content blocking All supported cPanel versions hit by critical auth bug, now patched U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog ShinyHunters exploit Anodot incident to target Vimeo CVE-2026-3854 GitHub flaw enables remote code execution Signal Phishing Campaign Targets German Officials in Suspected Russian Operation Microsoft fixes Entra ID flaw enabling privilege escalation New Android spyware Morpheus linked to Italian surveillance firm NCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort links Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software LINKEDIN BROWSERGATE Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting Fast16: Pre-Stuxnet malware that targeted precision engineering software Italy moves to extradite Chinese national to the U.S. over hacking charges U.S. utility giant Itron discloses a security breach Critical bug in CrowdStrike LogScale let attackers access files GopherWhisper: new China-linked APT targets Mongolia with Go-based malware SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94 Trigona ransomware adopts custom tool to steal data and evade detection Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITION U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog Over 400,000 sites at risk as hackers exploit Breeze Cache plugin flaw (CVE-2026-3844) CISA reports persistent FIRESTARTER backdoor on Cisco ASA device in federal network 12-year-old Pack2TheRoot bug lets Linux users gain root privileges Signal phishing campaign targets Germany’s Bundestag President Julia Klöckner
Broadcom releases VMware Fusion security update for root ...
Pierluigi Pa · 2026-05-14 · via Security Affairs

Broadcom patched a high-severity VMware Fusion flaw, CVE-2026-41702, that could let local attackers gain root privileges.

Broadcom released a security update for VMware Fusion to address a high-severity vulnerability, tracked as CVE-2026-41702, that could allow local attackers to escalate privileges to root on affected systems.

The flaw is a time-of-check time-of-use (TOCTOU) vulnerability affecting operations performed by a SETUID binary that was reported by security researcher Mathieu Farrell.

Broadcom explained that an attacker with local non-administrative user privileges can exploit the bug to escalate privileges to root on the system where Fusion is installed.

“A local privilege escalation vulnerability in VMware Fusion was privately reported to Broadcom.” reads the advisory. “Updates are available to remediate this vulnerability in affected Broadcom products.”

Successful exploitation could allow attackers with limited access to gain full control of vulnerable machines, significantly increasing the risk posed by compromised user accounts or insider threats.

TOCTOU vulnerabilities occur when a system checks the state of a resource and later uses it without ensuring that the state has not changed in the meantime. Attackers can exploit this timing gap to manipulate files, permissions, or other resources and execute unauthorized actions with elevated privileges.

VMware Fusion is widely used by developers, IT professionals, and security researchers to run virtual machines on macOS systems. Because the vulnerability requires local access, it does not expose systems directly to remote compromise. However, privilege escalation flaws remain highly valuable to attackers because they can turn a limited foothold into complete system compromise.

The patch arrives as Broadcom participates in the Pwn2Own hacking competition taking place this week in Berlin. The event, organized by Trend Micro’s Zero Day Initiative, brings together some of the world’s top security researchers to demonstrate zero-day exploits targeting widely used enterprise and consumer technologies.

VMware products have historically attracted strong interest from Pwn2Own participants due to the high value of virtualization exploits. This year, participants are expected to showcase attacks against VMware ESX, with successful demonstrations potentially earning rewards of up to $200,000.

Interestingly, VMware Workstation, which has frequently appeared as a target in previous Pwn2Own editions and generated significant payouts for researchers, was removed from this year’s list of eligible targets.

Organizations and users running VMware Fusion are advised to apply the latest updates as soon as possible to reduce the risk of privilege escalation attacks.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, VMware Fusion)