Executive brief
Waves Central, a management application for professional audio plugins, contains a security flaw on macOS that allows a local user to gain administrative (root) control of the computer. By exploiting improper security settings in a helper component, an attacker can inject malicious code into a trusted process and trick the system into performing high-privilege tasks. This could lead to full system compromise, unauthorized data access, or the installation of persistent malware.
Technical details
Waves Central for macOS (v13.0.9 - 16.5.5) includes a trusted XPC client component, 'InstlHelperApplication', signed with 'com.apple.security.cs.allow-dyld-environment-variables' and 'com.apple.security.cs.disable-library-validation' entitlements. These hardened runtime exceptions allow a local attacker to use the DYLD_INSERT_LIBRARIES environment variable to inject an unsigned, malicious dynamic library into the process. Because the injected code runs within a process possessing a valid Developer ID signature, it can successfully bypass client validation checks when connecting to the 'com.waves.central.InstlHelper' privileged Mach service. An attacker can then invoke privileged methods, such as 'executeIrlFileWithPath', to execute arbitrary commands with root privileges. The vulnerability is resolved in version 16.6.2.
Affected products
- Waves Audio Waves Central 13.0.9 - 16.5.5
Timeline
- 2026-01-07: disclosed: Vulnerability discovered by SEC Consult
- 2026-06-09: advisory: Public advisory and CVE assignment
- 2026-06-09: patched: Fixed in version 16.6.2