# macOS TimeMachine XPC flaws enabled root LPE

Published: 2026-08-02 · Severity: medium
Canonical: https://vorant.io/reports/c00482f6-7b66-59ac-925f-0dd72db3546f/macos-timemachine-xpc-flaws-enabled-root-lpe

> Two macOS local privilege escalation bugs (CVE-2019-8513, CVE-2019-8530) in TimeMachine diagnostic helpers allowed reliable root access; patched in 10.14.4.

Researchers detailed two local privilege escalation vulnerabilities affecting macOS 10.12.x through 10.14.3, both residing in Apple's TimeMachine diagnostic XPC helpers. CVE-2019-8530 is an arbitrary file write issue in the timemachinehelper XPC service, which fails to validate the destination directory before writing diagnostic logs, previously combinable with a since-patched sudo timestamp flaw to escalate privileges. CVE-2019-8513 is a command injection vulnerability in the tmdiagnose binary, where output from `diskutil list` is piped into an awk/system() call; by crafting a malicious disk image volume label containing CRLF and shell metacharacters, an attacker could inject arbitrary shell commands executed as root.

## Mentioned in this report

- Vulnerabilities: CVE-2019-8513 (weaponized), CVE-2019-8530

Source reporting: https://objective-see.org/blog/blog_0x40.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/c00482f6-7b66-59ac-925f-0dd72db3546f/macos-timemachine-xpc-flaws-enabled-root-lpe.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
