PT-2026-48400 · Slate Digital · Slate Digital Connect
CVE-2026-24066
·
Published
2026-06-10
·
Updated
2026-06-16
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Slate Digital Connect version 1.37.0
Description
The software installs a privileged helper tool, 'com.slatedigital.connect.privileged.helper.tool', which exposes the XPC service 'com.slatedigital.connect.privileged.helper.tool2'. The helper validates connecting XPC clients by checking only the
subject.OU value of the client's signing certificate and fails to verify that the certificate chains to a trusted code-signing authority. A local attacker can sign a malicious client with a self-signed certificate containing the expected organizational unit value to connect to the privileged XPC service, potentially leading to local privilege escalation through unauthorized access to privileged helper functionality.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Slate Digital Connect