PT-2026-47796 · Waves Audio · Waves Central

CVE-2026-24065

·

Published

2026-06-09

·

Updated

2026-06-09

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Waves Central for macOS versions 13.0.9 through 16.5.5
Description A local privilege escalation exists in the privileged helper service. The helper validates connecting XPC clients (a mechanism for inter-process communication) using the client process identifier PID to verify code-signing identity. Since process identifiers can be reused, a local attacker can exploit a race condition between the connection request and the validation process, leading the helper to trust a process controlled by the attacker. This allows the execution of privileged operations and arbitrary code as root.
Recommendations Update to version 16.6.2.

Exploit

Fix

LPE

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-24065

Affected Products

Waves Central