Privilege escalation via insecure temporary file handling in HP Easy Start for macOS
AI analysis
HP has released fixes for a privilege-escalation vulnerability in HP Easy Start for macOS, the company's printer setup and driver installation utility, affecting versions prior to 2.16.7.260722. The flaw is classified as CWE-379 (creation of temporary files with insecure permissions), meaning the software creates temporary files with weak permissions that a low-privileged attacker can potentially manipulate — for example via symlink or file-replacement tricks — while the software operates. According to the CVSS 4.0 vector (AV:N/AC:L/AT:P/PR:L/UI:N), successful exploitation requires certain conditions to be met and low-level privileges but no user interaction, and yields high impact on the confidentiality, integrity, and availability of the affected component without spreading to other systems. Any macOS user who installed HP Easy Start — typically bundled with HP printers or downloaded from HP's support site during printer setup — on a version before 2.16.7.260722 is affected; this CVE is one of three related issues (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556) addressed by the same update. There is no public proof of concept, the flaw is not in CISA KEV, and EPSS places exploitation probability at roughly 0.2% over the next 30 days, indicating no known exploitation activity.
What to do: Update HP Easy Start for macOS to version 2.16.7.260722 or later, available via HP's support site; since the utility is installed per-machine, inventory Macs for HP Easy Start and re-run its updater or reinstall from HP. In the meantime, restrict untrusted local accounts on shared macOS hosts, and treat this as a standard-cycle patch given the low EPSS score and absence of public exploits.
Affected
| HP Inc. HP Easy Start for macOS | All versions prior to 2.16.7.260722 |
Estimated exposure
massplausibly on the order of millions of macOS installations worldwide (HP printer setup utility, not a network-exposed service) — HP is the dominant consumer printer vendor and Easy Start is the default macOS setup path bundled with new HP printers and offered from HP's site, so the cumulative installed base is likely large, though the subset of Macs still running a…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.