Description
Intego Log Reporter, a macOS diagnostic utility bundled with Intego security products that collects system and application logs for support analysis, contains a local privilege escalation vulnerability. A root-executed diagnostic script creates and writes files in /tmp without enforcing secure directory handling, introducing a time-of-check to time-of-use (TOCTOU) race condition. A local unprivileged user can exploit a symlink-based race condition to cause arbitrary file writes to privileged system locations, resulting in privilege escalation to root.
INFO
Published Date :
2026-02-12T21:58:19.803Z
Last Modified :
2026-03-23T15:44:16.165Z
Source :
VulnCheck
AFFECTED PRODUCTS
The following products are affected by CVE-2026-26224 vulnerability.
| Vendors | Products |
|---|---|
| Intego |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-26224.