Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-24065— Local Privilege Escalation via Insecure XPC Client Validation in Waves Central for macOS

Quick assessment

Affected
Waves Audio Ltd. Waves Central
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Waves Central是Waves公司的一款音频软件许可证与产品管理工具。 Waves Central for macOS 13.0.9版本至16.5.5版本存在安全漏洞,该漏洞源于特权助手服务使用进程标识符验证XPC客户端,可能导致本地攻击者利用竞争条件使助手信任攻击者控制的进程,从而以root权限执行任意代码。

AI Predicted 7.8 Difficulty: Moderate EPSS 0.32% · P25

Affected Version Matrix 1

VendorProduct Version RangeStatus
Waves Audio Ltd. Waves Central 13.0.9≤ 16.5.5 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-24065

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Local Privilege Escalation via Insecure XPC Client Validation in Waves Central for macOS
Source: CVE Program / CVE List V5
Vulnerability Description
Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability in the privileged helper service. The helper validates connecting XPC clients using the client process identifier (PID) to verify code-signing identity. Because process identifiers can be reused, a local attacker can exploit a race condition between the time a connection request is made and the time the helper performs validation, causing the helper to trust an attacker-controlled process. This allows the attacker to invoke privileged operations, resulting in arbitrary code execution as root. The issue is fixed in version 16.6.2.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
检查时间与使用时间(TOCTOU)的竞争条件
Source: CVE Program / CVE List V5
Vulnerability Title
Waves Central 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Waves Central是Waves公司的一款音频软件许可证与产品管理工具。 Waves Central for macOS 13.0.9版本至16.5.5版本存在安全漏洞,该漏洞源于特权助手服务使用进程标识符验证XPC客户端,可能导致本地攻击者利用竞争条件使助手信任攻击者控制的进程,从而以root权限执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Waves Audio Ltd. Waves Central 13.0.9 ~ 16.5.5 -

II. Public POCs for CVE-2026-24065

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-24065

登录查看更多情报信息。

Vendor Advisories for CVE-2026-24065 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-24065

No comments yet


Leave a comment