Trend Micro Apex One (Mac) Agent Cache Mechanism Time-of-Check Time-of-Use Local Privilege Escalation Vulnerability

Vulnerability

A time-of-check time-of-use vulnerability has been identified in the cache mechanism of the Trend Micro Apex One (Mac) agent. This vulnerability could allow a local attacker to escalate privileges on affected installations. The issue arises from improper cache key validation during signature verification, enabling an attacker to gain elevated rights and execute arbitrary code with root privileges. To exploit this vulnerability, an attacker must first have the ability to run low-privileged code on the target system.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing a local attacker to execute code with elevated rights, potentially compromising the entire system.

Remediation

Trend Micro has released a Critical Patch for Apex One (Mac) to address this vulnerability. More details can be found on the Trend Micro Success Portal.

Added: May 21, 2026, 2:48 PM
Updated: May 21, 2026, 2:48 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
3.1
remediation
7.7
relevance
8.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.