
Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS
securityvulnerabilityprivilege-escalationmacOSHPCVEcybersecuritysoftware-update
Three high-severity privilege-escalation vulnerabilities have been identified in HP Easy Start for macOS, with CVSS ratings of 8.5, 7.7, and 7.7. The research examines trust boundaries around privileged components and how they can fail in practice. HP has published an advisory and released an updated version to address these vulnerabilities. The vulnerabilities are tracked as CVE-2026-12554, CVE-2026-12555, and CVE-2026-12556.