No advisories yet.
Solution
The issue is fixed in version 16.6.2 or higher which can be downloaded at the vendor's download page at https://www.waves.com/downloads/central
Workaround
No workaround given by the vendor.
Tue, 09 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Waves Audio
Waves Audio waves Central |
|
| Vendors & Products |
Waves Audio
Waves Audio waves Central |
Tue, 09 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
cvssV3_1
|
Tue, 09 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability in the privileged helper service. The helper validates connecting XPC clients using the client process identifier (PID) to verify code-signing identity. Because process identifiers can be reused, a local attacker can exploit a race condition between the time a connection request is made and the time the helper performs validation, causing the helper to trust an attacker-controlled process. This allows the attacker to invoke privileged operations, resulting in arbitrary code execution as root. The issue is fixed in version 16.6.2. | |
| Title | Local Privilege Escalation via Insecure XPC Client Validation in Waves Central for macOS | |
| Weaknesses | CWE-367 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: SEC-VLab
Published:
Updated: 2026-06-09T15:58:35.788Z
Reserved: 2026-01-21T11:29:19.853Z
Link: CVE-2026-24065
Updated: 2026-06-09T15:54:43.741Z
Status : Deferred
Published: 2026-06-09T16:16:39.477
Modified: 2026-06-09T19:36:10.547
Link: CVE-2026-24065
No data.
OpenCVE Enrichment
Updated: 2026-06-09T20:20:31Z