CVE-2025-7779
8.8Acronis · True Image
An insecure XPC service configuration in Acronis True Image for macOS allows a local user to escalate privileges to a higher level.
Executive summary
A local privilege escalation vulnerability in multiple Acronis True Image products on macOS poses a significant risk of unauthorized system-level access.
Vulnerability
This vulnerability involves an insecure XPC service configuration (CWE-269), which permits an authenticated local user to perform actions with elevated privileges.
Business impact
Successful exploitation of this vulnerability allows a local attacker to achieve total system control, potentially leading to full system compromise, data theft, or the installation of persistent malicious software. With a CVSS score of 8.8, this flaw represents a high-severity risk that could severely impact the integrity and confidentiality of the affected macOS systems.
Remediation
Immediate Action: Update all affected Acronis True Image installations to the specific build versions listed in the vendor advisory to remediate the insecure XPC service configuration.
Proactive Monitoring: Monitor system logs for unusual XPC communication patterns or unauthorized process execution attempts originating from standard user accounts.
Compensating Controls: Restrict local user access to the extent possible and ensure that only trusted applications are installed on systems running the affected software.
Exploitation status
Public Exploit Available: No (exploit_available unknown).
Analyst recommendation
Given the high CVSS score and the ability for a local attacker to gain total control, organizations must prioritize patching these Acronis products immediately. Applying the specified build updates is the only definitive way to resolve the underlying configuration flaw and secure the affected macOS environments.
More Acronis CVEs
History
- Disclosed CVE record published
- Published in the daily brief high section
- Published in the daily brief high section
- Analyst report written
- Fix documented version 42389 per CVE record
Sources
Originally found and disclosed by @nullevent (https://hackerone.com/nullevent), Carlos Garrido (https://pentraze.com/vulnerability-reports), Pentraze Cyber Security (https://pentraze.com/vulnerability-reports), per the CVE Program record.
- SEC-8193 Vendor advisory