Vulnerabilities & PatchesEmerging1 src
Three HP Easy Start Vulnerabilities Expose macOS Systems to Root-Level Attacks
Three high-severity vulnerabilities in HP Easy Start for macOS could enable local attackers and, in limited scenarios, network-positioned adversaries to interfere with printer software installation workflows and modify files through a privileged execution path.
Tracked as CVE-2026-12554, CVE-2026-12555, and CVE-2026-12556, the flaws were identified by Nir Yehoshua of Cipher Security Labs during an assessment of HP Easy Start version 2. 16. 0. HP addressed the issues in version 2. 16. 7. 260722 under a security bulletin.
CVE-2026-12555 is the most direct local privilege-related issue. The flaw affects the HP Easy Start Uninstaller, which used predictable, world-writable file locations in /tmp and /private/tmp after the user approved an administrative elevation prompt.