Junglewise Threat Intelligence

CVE-2025-65841: Acustica Audio Aquarius Desktop weak credential encryption in macOS settings

CVE-2025-65841 · Severity: medium · CVSS 6.2 · Published 2025-12-03

Executive brief

Aquarius Desktop, a management application for audio plugins, stores user login passwords on the local computer using a weak protection method. Because the encryption uses a fixed key that is the same for every user, an attacker with access to the computer can easily recover the original password. This could lead to a full takeover of the user's account, allowing unauthorized access to purchased software and cloud-synchronized data.

Technical details

Aquarius Desktop 3.0.069 for macOS stores plaintext-equivalent credentials in '~/Library/Application Support/Aquarius/aquarius.settings'. The application uses Blowfish encryption in ECB mode with a hardcoded, static key ('potkseD suoirauqA') and no device-specific binding or salts. An attacker with local file system access can exfiltrate this file to impersonate the user on another machine or use a simple script to reverse the byte-substitution and endianness-swapping to recover the plaintext password. This vulnerability can be chained with local privilege escalation flaws to compromise accounts of other users on the same system.

Affected products

  • Acustica Audio Aquarius Desktop 3.0.069

Timeline

  • 2025-08-02: other: Vulnerability discovered during local security analysis
  • 2025-08-19: other: Responsible disclosure email sent to vendor
  • 2025-11-19: disclosed: Public disclosure by researcher
  • 2025-12-03: advisory: CVE published to NVD

References