Security researchers found ‘critical’ flaw in IPVanish Mac VPN app – here’s everything you need to know


  • Security researchers found a critical flaw in the IPVanish Mac VPN app
  • The flaw could allow attackers to gain full control of a user’s system
  • IPVanish is said to be “working on a fix”, ensuring that only OpenVPN is affected

A “critical privilege escalation vulnerability” has been discovered in the IPVanish VPN application for macOS, potentially allowing malicious actors to gain full control of a user’s system.

Discovered by cybersecurity researchers at SecureLayer7, the flaw exploits the VPN’s “privileged utility,” a background component used to manage secure network connections. The researchers found that this tool makes only a very limited effort to verify who is asking to run commands. As a result, “the flaw allows any unprivileged local process to execute arbitrary code as root without user interaction,” experts warn.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top