Multiple Local Privilege Escalation Vulnerabilities in Waves Audio
Waves Central was found to be vulnerable to Local Privilege Escalation via multiple vectors. The privileged helper utilized by Waves Central via XPC did not perform secure client validation. A DYLIB Injection vulnerability allowed to inject code into a validly signed binary, leading to an attacker being able to connect to the privileged helper. CVE-2026-24064, CVE-2026-24065


