Executive brief
Waves Central is a software management application for macOS audio plugins. A local authenticated user can exploit improper security checks in the privileged helper service to execute arbitrary code with root privileges, potentially compromising system security and allowing unauthorized access to all files and settings.
Technical details
Waves Central contains a missing authorization vulnerability (CWE-862) in its privileged XPC helper service. The helper authenticates connecting clients by comparing code-signing certificate chains for equality rather than validating against a pinned code requirement (application identifier and Team ID). A local authenticated attacker can execute code within a vendor-signed process, bypass the helper's client check, and trick the helper into executing arbitrary scripts with root privileges. The vulnerability affects versions 16.6.2 through 16.x and is fixed in version 17.0.
Affected products
- Waves Audio Ltd. Waves Central 16.6.2 to 16.x (fixed in 17.0)
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: Version 17.0 contains the fix