CVE-2026-11626
Description
CleanWipe Removal Tool for macOS (prior to 16.0.0.65) has a local privilege escalation vulnerability allowing limited-privilege users to gain administrative control.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CleanWipe Removal Tool for macOS (prior to 16.0.0.65) has a local privilege escalation vulnerability allowing limited-privilege users to gain administrative control.
Vulnerability
The CleanWipe Removal Tool for macOS, versions prior to 16.0.0.65, is susceptible to a local privilege escalation vulnerability. This issue allows an attacker with limited privilege access on an affected system to escalate their privileges to gain administrative control [1].
Exploitation
An attacker with limited privilege access on an affected system can exploit this vulnerability. The exact conditions and sequence of steps required for exploitation are not detailed in the available references, but it involves leveraging the limited privileges to escalate to administrative control [1].
Impact
Successful exploitation of this vulnerability allows an attacker to escalate their privileges from limited access to full administrative control over the affected macOS system. This grants the attacker the highest level of privilege on the system [1].
Mitigation
An update, MacOS_CleanWipe_EA_16.0.0.65, has been released to address this issue. The latest version of the CleanWipe Removal tool can be obtained via the "Download the CleanWipe removal tool to uninstall Endpoint Protection" knowledge base article. Broadcom also recommends restricting administrative access, remote access, running under least privilege, keeping systems updated, and employing multi-layered security and intrusion detection systems [1].
AI Insight generated on Jun 10, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <16.0.0.65
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
0No linked articles in our index yet.