CVE-2018-7493: Cactusvpn

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

CactusVPN through 6.0 for macOS suffers from a root privilege escalation vulnerability in its privileged helper tool. The privileged helper tool implements an XPC interface, which allows arbitrary applications to execute system commands as root.

Affected products

Published 2018-03-05. Last modified 2026-06-17.