ZeroHour
Full Disclosurepublished ()ingested

HP Easy Start for macOS: CVE-2026-12554 / CVE-2026-12555 / CVE-2026-12556

AI summary · glm-5.3-flash

Cipher Security Labs disclosed three high-severity macOS privilege vulnerabilities in HP Easy Start, fixed in version 2.16.7.260722.

HP Easy Start for macOS contains three high-severity vulnerabilities, CVE-2026-12554, CVE-2026-12555, and CVE-2026-12556, that break the product's macOS privilege boundaries. The issues were researched by Cipher Security Labs and coordinated with HP under advisory HPSBPI04124. Fixes are available in HP Easy Start 2.16.7.260722 and later versions.

  • Three high-severity flaws affect HP Easy Start for macOS privilege boundaries.
  • Coordinated disclosure with HP under advisory HPSBPI04124.
  • Fixed in HP Easy Start 2.16.7.260722 and later.
VendorsHP

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-12554
+2 in the same advisory: …12555 …12556
Local Privilege Escalation in HP Easy Start for macOS

HP has disclosed local privilege escalation vulnerabilities in HP Easy Start for macOS, the company's printer installation and setup utility, affecting all versions prior to 2.16.7.260722. The CWE-1104 mapping indicates the flaws are associated with the use of unmaintained third-party components bundled with the tool. Per the CVSS 4.0 vector, a local attacker with only low privileges, and requiring no user interaction, can leverage the flaw to gain escalated privileges with high impact on the confidentiality, integrity, and availability of the affected machine. Any macOS user who has installed HP Easy Start to set up an HP printer is affected until they apply the updated version. There is no evidence of active exploitation: no public proof-of-concept exists, the flaw is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days.

Do: Update HP Easy Start for macOS to version 2.16.7.260722 or later, obtained from HP's official support site; the same release also addresses the related issues CVE-2026-12555 and CVE-2026-12556. Verify the installed version on managed Macs, prioritizing shared or multi-user machines where local privilege escalation poses the greatest risk. No workarounds are described in the advisory, so patching is the primary mitigation.

8.5
group max
<1%
  • HP Easy Start for macOS All versions prior to 2.16.7.260722
massLikely millions of cumulative macOS installations (current active installs uncertain)
Full article

Posted by Nir Yehoshua on Sep 03 Hello Full Disclosure list, Cipher Security Labs has published technical details for three High-severity vulnerabilities affecting HP Easy Start for macOS. The issues were coordinated with HP and are addressed in HP Easy Start 2.16.7.260722 and later under HPSBPI04124. Research title: Rooted in Trust: Breaking HP Easy Start’s macOS Privilege Boundaries Affected product: HP Easy Start for macOS Affected versions: Versions prior to...

This source does not provide full text. Read it at seclists.org.