Three high-severity privilege-escalation vulnerabilities (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556) in HP Easy Start for macOS exploit broken trust boundaries between privileged components. The vulnerabilities have CVSS scores of 8.5, 7.7, and 7.7. HP has published an advisory and released an updated version.
Three high-severity vulnerabilities in HP Easy Start for macOS, rated CVSS 8.5, 7.7 and 7.7. The research looks at the trust boundaries around privileged components and how they can break down in practice. HP has published an advisory and released an updated version. Disclosure: I’m the researcher who reported these vulnerabilities. submitted by /u/ciphersecuritylabs [link] [comments]