CVE-2026-78236: Admin By Request Abr

High severity, CVSS 8.8. EPSS: 0.1% chance of exploitation in the next 30 days.

An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as an Apple-signed process.

Affected products

Published 2026-08-26. Last modified 2026-09-03.