Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability in the privileged helper service. The helper validates connecting XPC clients using the client process identifier (PID) to verify code-signing identity. Because process identifiers can be reused, a local attacker can exploit a race condition between the time a connection request is made and the time the helper performs validation, causing the helper to trust an attacker-controlled process. This allows the attacker to invoke privileged operations, resulting in arbitrary code execution as root. The issue is fixed in version 16.6.2.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
cvssV3_1
|
Tue, 09 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability in the privileged helper service. The helper validates connecting XPC clients using the client process identifier (PID) to verify code-signing identity. Because process identifiers can be reused, a local attacker can exploit a race condition between the time a connection request is made and the time the helper performs validation, causing the helper to trust an attacker-controlled process. This allows the attacker to invoke privileged operations, resulting in arbitrary code execution as root. The issue is fixed in version 16.6.2. | |
| Title | Local Privilege Escalation via Insecure XPC Client Validation in Waves Central for macOS | |
| Weaknesses | CWE-367 | |
| References |
|
Status: PUBLISHED
Assigner: SEC-VLab
Published:
Updated: 2026-06-09T15:58:35.788Z
Reserved: 2026-01-21T11:29:19.853Z
Link: CVE-2026-24065
Updated: 2026-06-09T15:54:43.741Z
Status : Deferred
Published: 2026-06-09T16:16:39.477
Modified: 2026-06-09T19:36:10.547
Link: CVE-2026-24065
No data.
OpenCVE Enrichment
Updated: 2026-06-09T17:30:10Z