Local Privilege Escalation Vulnerability in Waves Central for macOS
CVE-2026-24064

7.8HIGH

Key Information:

Vendor
CVE Published:
9 June 2026

What is CVE-2026-24064?

Waves Central for macOS has a local privilege escalation vulnerability that affects versions 13.0.9 through 16.5.5. The issue arises from a trusted XPC client component that is improperly signed with hardened runtime entitlements, allowing an attacker to inject a dynamic library into the trusted client process using the DYLD_INSERT_LIBRARIES environment variable. This exploitation can lead to executing arbitrary code with root privileges through a connected privileged helper service. The vulnerability has been addressed in version 16.6.2.

Affected Version(s)

Waves Central MacOS 13.0.9 <= 16.5.5

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Florian Haselsteiner, SEC Consult Vulnerability Lab
.