Local Privilege Escalation Vulnerability in Waves Central for macOS
CVE-2026-24065

8.1HIGH

Key Information:

Vendor
CVE Published:
9 June 2026

What is CVE-2026-24065?

Waves Central for macOS has a local privilege escalation vulnerability that allows an attacker to exploit a race condition in the privileged helper service. The vulnerability arises from the method of validating connecting XPC clients through the client process identifier (PID). This can be manipulated by local attackers due to PID reuse, enabling them to deceive the helper into trusting a malicious process. Consequently, this grants the attacker the ability to perform privileged operations and execute arbitrary code with root privileges. The issue has been addressed in version 16.6.2.

Affected Version(s)

Waves Central MacOS 13.0.9 <= 16.5.5

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Florian Haselsteiner, SEC Consult Vulnerability Lab
.