ZeroHour

CVE-2026-12554

mass

Local Privilege Escalation in HP Easy Start for macOS

CVSS 4.0
8.5 high
EPSS
<1%p11
Published
()
Modified
AI analysis

HP has disclosed local privilege escalation vulnerabilities in HP Easy Start for macOS, the company's printer installation and setup utility, affecting all versions prior to 2.16.7.260722. The CWE-1104 mapping indicates the flaws are associated with the use of unmaintained third-party components bundled with the tool. Per the CVSS 4.0 vector, a local attacker with only low privileges, and requiring no user interaction, can leverage the flaw to gain escalated privileges with high impact on the confidentiality, integrity, and availability of the affected machine. Any macOS user who has installed HP Easy Start to set up an HP printer is affected until they apply the updated version. There is no evidence of active exploitation: no public proof-of-concept exists, the flaw is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days.

What to do: Update HP Easy Start for macOS to version 2.16.7.260722 or later, obtained from HP's official support site; the same release also addresses the related issues CVE-2026-12555 and CVE-2026-12556. Verify the installed version on managed Macs, prioritizing shared or multi-user machines where local privilege escalation poses the greatest risk. No workarounds are described in the advisory, so patching is the primary mitigation.

Affected
HP Easy Start for macOSAll versions prior to 2.16.7.260722
Estimated exposure
massLikely millions of cumulative macOS installations (current active installs uncertain) — HP is one of the world's largest printer vendors and Easy Start is its default printer-setup path for macOS, so cumulative deployments are plausibly in the millions, though as a setup-time utility many installations may no longer be…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.

Weakness
CWE-1104
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

HP Easy Start for macOS: CVE-2026-12554 / CVE-2026-12555 / CVE-2026-12556

Cipher Security Labs disclosed three high-severity macOS privilege vulnerabilities in HP Easy Start, fixed in version 2.16.7.260722.

HP Easy Start for macOS contains three high-severity vulnerabilities, CVE-2026-12554, CVE-2026-12555, and CVE-2026-12556, that break the product's macOS privilege boundaries. The issues were researched by Cipher Security Labs and coordinated with HP under advisory HPSBPI04124. Fixes are available in HP Easy Start 2.16.7.260722 and later versions.