CVE-2026-24065
HIGHLocal Privilege Escalation via Insecure XPC Client Validation in Waves Central for macOS
Title source: cnaDescription
Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability in the privileged helper service. The helper validates connecting XPC clients using the client process identifier (PID) to verify code-signing identity. Because process identifiers can be reused, a local attacker can exploit a race condition between the time a connection request is made and the time the helper performs validation, causing the helper to trust an attacker-controlled process. This allows the attacker to invoke privileged operations, resulting in arbitrary code execution as root. The issue is fixed in version 16.6.2.
References (2)
Core 2
Core References
Third Party Advisory third-party-advisory
https://r.sec-consult.com/waves
Scores
CVSS v3
8.1
EPSS
0.0026
EPSS Percentile
17.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-367
Status
published
Products (1)
Waves Audio Ltd./Waves Central
13.0.9 - 16.5.5
Published
Jun 09, 2026
Tracked Since
Jun 09, 2026