CVE-2026-2637

iBoysoft NTFS for Mac contains a local privilege escalation vulnerability in its privileged helper daemon ntfshelperd. The daemon exposes an NSConnection service that runs as root without implementing any authentication or authorization checks. This issue affects iBoysoft NTFS: 8.0.0.
References
Link Resource
https://fluidattacks.com/advisories/cuarteto Exploit Third Party Advisory
https://iboysoft.com/ntfs-for-mac/ Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:iboysoft:ntfs_for_mac:8.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-03 15:16

Updated : 2026-06-17 10:31


NVD link : CVE-2026-2637

Mitre link : CVE-2026-2637

CVE.ORG link : CVE-2026-2637


JSON object : View

Products Affected

iboysoft

  • ntfs_for_mac
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource