Executive brief
Arturia Software Center, a management tool for music production plugins on macOS, contains a security flaw in how it handles uninstallation scripts. When a plugin is installed, it creates an uninstallation file with insecure permissions that allow any user on the computer to modify it. If a malicious user edits this file, their code will be executed with full administrative (root) privileges when the software is later uninstalled, potentially leading to a complete system takeover.
Technical details
The vulnerability is classified as Incorrect Default Permissions (CWE-276). When Arturia Software Center installs a plugin on macOS, it places an 'uninstall.sh' bash script in a root-owned directory (e.g., /Library/Arturia/...) with 777 (world-writable) permissions. A local attacker can modify the contents of this script. When a user or the system triggers an uninstallation via the Arturia Software Center, the 'Privileged Helper' component executes this script with root privileges via XPC. This allows the attacker's arbitrary code to run as root, resulting in local privilege escalation (LPE). As of the advisory date, the vendor has been unresponsive and no patch is available.
Affected products
- Arturia Software Center (MacOS) 2.12.0.3157
Timeline
- 2026-01-02: other: Vulnerability discovered by SEC Consult
- 2026-01-05: other: Initial vendor contact attempt
- 2026-03-18: disclosed: Public release of advisory
- 2026-03-18: advisory: NVD publication date