Junglewise Threat Intelligence

CVE-2026-24065: Waves Audio Waves Central local privilege escalation in privileged helper service

CVE-2026-24065 · Severity: info · CVSS 7.8 · Published 2026-06-09

Technologies: Waves Audio Waves Central. Vendors: Waves Audio.

Executive brief

Waves Central, a management application for professional audio software, contains a security flaw in its background helper service on macOS. A local user on the computer can exploit a timing issue to trick this service into granting administrative access. If successful, an attacker can execute commands with the highest system privileges (root), potentially leading to full system takeover, data theft, or permanent modification of the operating system.

Technical details

The privileged helper service 'com.waves.central.InstlHelper' in Waves Central for macOS (v13.0.9 - v16.5.5) performs insecure client validation of XPC connections. The service relies on the Process Identifier (PID) of the connecting client to verify its code-signing identity. Because PIDs are finite and recycled by the operating system, a local attacker can exploit a Time-of-Check Time-of-Use (TOCTOU) race condition. By timing a connection request such that a legitimate process terminates and its PID is reassigned to a malicious process before the helper performs its validation check, the attacker can bypass signature verification. This allows the attacker to invoke privileged methods such as 'executeIrlFileWithPath', resulting in arbitrary code execution with root privileges. The issue is addressed in version 16.6.2.

Affected products

  • Waves Audio Waves Central 13.0.9 through 16.5.5

Timeline

  • 2026-01-07: other: Vulnerability discovered by SEC Consult
  • 2026-06-09: disclosed: Public disclosure of CVE-2026-24065
  • 2026-06-09: patched: Fixed in version 16.6.2

References