CVE-2026-2637
Received
Received - Intake
Local Privilege Escalation in iBoysoft NTFS ntfshelperd Daemon
Publication date: 2026-03-03
Last updated on: 2026-04-27
Assigner: Fluid Attacks
Description
Description
iBoysoft NTFS for Mac contains a local privilege escalation vulnerability in its privileged helper daemon ntfshelperd. The daemon exposes an NSConnection service that runs as root without implementing any authentication or authorization checks.
This issue affects iBoysoft NTFS: 8.0.0.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| iboysoft | ntfs_for_mac | 8.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-732 | The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. |