Description

Intego Personal Backup, a macOS backup utility that allows users to create scheduled backups and bootable system clones, contains a local privilege escalation vulnerability. Backup task definitions are stored in a location writable by non-privileged users while being processed with elevated privileges. By crafting a malicious serialized task file, a local attacker can trigger arbitrary file writes to sensitive system locations, leading to privilege escalation to root.

INFO

Published Date :

2026-02-12T21:57:54.796Z

Last Modified :

2026-03-23T15:44:16.931Z

Source :

VulnCheck
AFFECTED PRODUCTS

The following products are affected by CVE-2026-26225 vulnerability.

Vendors Products
Intego
  • Personal Backup

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability