CVE-2024-14032
HIGHTwitch Studio LauncherHelper XPC Missing Authorization to Root File Write
Title source: cnaDescription
Twitch Studio version 0.114.8 and prior contain a privilege escalation vulnerability in its privileged helper tool that allows local attackers to execute arbitrary code as root by exploiting an unprotected XPC service. Attackers can invoke the installFromPath:toPath:withReply: method to overwrite system files and privileged binaries, achieving full system compromise. Twitch Studio was discontinued in May 2024.
References (4)
Core 4
Core References
Exploit technical-description
exploit
https://www.iru.com/blog/twitch-privileged-helper
Product product
https://help.twitch.tv/s/topic/0TO3a000000kZfYGAU/twitch-studio
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/twitch-studio-launcherhelper-xpc-missing-authorization-to-root-file-write
Scores
CVSS v3
7.8
EPSS
0.0018
EPSS Percentile
7.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-862
Status
published
Products (2)
Twitch/Twitch Studio
< 0.114.8
twitch/twitch_studio
< 0.114.8
Published
Apr 06, 2026
Tracked Since
Apr 06, 2026