Executive brief
Aquarius Desktop, a management application for audio plugins, stores user login passwords on the local computer using a weak protection method. Because the encryption uses a fixed key that is the same for every user, an attacker with access to the computer can easily recover the original password. This could lead to a full takeover of the user's account, allowing unauthorized access to purchased software and cloud-synchronized data.
Technical details
Aquarius Desktop 3.0.069 for macOS stores plaintext-equivalent credentials in '~/Library/Application Support/Aquarius/aquarius.settings'. The application uses Blowfish encryption in ECB mode with a hardcoded, static key ('potkseD suoirauqA') and no device-specific binding or salts. An attacker with local file system access can exfiltrate this file to impersonate the user on another machine or use a simple script to reverse the byte-substitution and endianness-swapping to recover the plaintext password. This vulnerability can be chained with local privilege escalation flaws to compromise accounts of other users on the same system.
Affected products
- Acustica Audio Aquarius Desktop 3.0.069
Timeline
- 2025-08-02: other: Vulnerability discovered during local security analysis
- 2025-08-19: other: Responsible disclosure email sent to vendor
- 2025-11-19: disclosed: Public disclosure by researcher
- 2025-12-03: advisory: CVE published to NVD