CVE-2026-24062 PUBLISHED

Insufficient XPC Client validation leading to local privilege escalation in Arturia Software Center

Assigner: SEC-VLab
Reserved: 21.01.2026 Published: 18.03.2026 Updated: 18.03.2026

The "Privileged Helper" component of the Arturia Software Center (MacOS) does not perform sufficient client code signature validation when a client connects. This leads to an attacker being able to connect to the helper and execute privileged actions leading to local privilege escalation.

Product Status

Vendor Arturia
Product Software Center
Versions Default: unknown
  • Version 2.12.0.3157 is affected

Solutions

The vendor was unresponsive and did not respond to any of our communication attempts. Therefore, a patch is not available. In case you are using this product, please approach the vendor and demand a fix.

Credits

  • Florian Haselsteiner, SEC Consult Vulnerability Lab finder

References

Problem Types

  • CWE-306 Missing authentication for critical function CWE

Impacts

  • CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs