Broadcom released a security update for VMware Fusion to fix CVE-2026-41702, a high-severity local privilege escalation flaw that could allow a non-administrative local user to gain root on affected macOS systems. The bug is a time-of-check time-of-use (TOCTOU) issue in operations performed by a SETUID binary, meaning attackers who already have local access could escalate privileges and potentially take full control of a vulnerable machine.
The vulnerability affects VMware Fusion versions prior to 26H1, according to Broadcom's advisory, which was also highlighted by the Canadian Centre for Cyber Security. The flaw was privately reported by security researcher Mathieu Farrell, and officials urged users and administrators to review the vendor advisory and apply the update promptly, particularly because VMware Fusion is widely used by developers, IT teams, and security researchers, increasing the risk from compromised accounts or insider misuse.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-14, the Canadian Centre for Cyber Security issued advisory AV26-469 referencing Broadcom's VMware Fusion vulnerability notice and urged administrators to review the advisory and apply the necessary updates.
On 2026-05-14, Broadcom published a security advisory and released updates for VMware Fusion to fix CVE-2026-41702, a high-severity local privilege escalation vulnerability affecting versions prior to 26H1.
Security researcher Mathieu Farrell privately reported CVE-2026-41702, a TOCTOU privilege escalation issue in a VMware Fusion SETUID binary that could let a non-administrative local user gain root access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.