Time-of-check Time-of-use (TOCTOU) Race Condition in Defender for Endpoint for macOS - CVE-2026-56178

 

Time-of-check Time-of-use (TOCTOU) Race Condition in Defender for Endpoint for macOS - CVE-2026-56178

Published: July 17, 2026


Vulnerability identifier: #VU138267
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-56178
CWE-ID: CWE-367
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint for Mac, which leads to security restrictions bypass and privilege escalation.


Affected software

Defender for Endpoint for macOS

How to mitigate CVE-2026-56178

Install updates from vendor's website.

Defender for Endpoint for macOS - update to 101.26042.0020

External References

Related Security Bulletins