Junglewise Threat Intelligence

CVE-2026-24062: Arturia Software Center insufficient XPC validation in Privileged Helper

CVE-2026-24062 · Severity: high · CVSS 7.8 · Published 2026-03-18

Executive brief

The Arturia Software Center for macOS, which manages the installation of music software and plugins, contains a security flaw in its background management service. This vulnerability allows a local user with limited permissions to gain full administrative (root) control over the computer. An attacker could use this access to steal sensitive data, install persistent malware, or disable system security features.

Technical details

The 'Privileged Helper' component (com.Arturia.InstallHelper) of the Arturia Software Center for macOS fails to perform sufficient client code signature validation when establishing XPC connections. This missing authentication allows any local process to connect to the helper and trigger privileged XPC commands. Specifically, an attacker can use the 'FINISHM' command to manipulate symlinks and the 'UNINSTA' command to execute arbitrary shell scripts as root. As of the advisory date, the vendor has been unresponsive and no patch is available.

Affected products

  • Arturia Software Center (MacOS) 2.12.0.3157

Timeline

  • 2026-01-02: other: Vulnerability discovered by SEC Consult
  • 2026-01-05: other: Initial vendor contact attempt
  • 2026-03-18: advisory: Public release of advisory by SEC Consult
  • 2026-03-18: disclosed: CVE published to NVD

References

Related threats