Local Privilege Escalation Vulnerability in Waves Central for macOS
CVE-2026-24064
7.8HIGH
What is CVE-2026-24064?
Waves Central for macOS has a local privilege escalation vulnerability that affects versions 13.0.9 through 16.5.5. The issue arises from a trusted XPC client component that is improperly signed with hardened runtime entitlements, allowing an attacker to inject a dynamic library into the trusted client process using the DYLD_INSERT_LIBRARIES environment variable. This exploitation can lead to executing arbitrary code with root privileges through a connected privileged helper service. The vulnerability has been addressed in version 16.6.2.
Affected Version(s)
Waves Central MacOS 13.0.9 <= 16.5.5
