High severity7.8NVD Advisory· Published Apr 6, 2026· Updated Apr 14, 2026
CVE-2024-14032
CVE-2024-14032
Description
Twitch Studio version 0.114.8 and prior contain a privilege escalation vulnerability in its privileged helper tool that allows local attackers to execute arbitrary code as root by exploiting an unprotected XPC service. Attackers can invoke the installFromPath:toPath:withReply: method to overwrite system files and privileged binaries, achieving full system compromise. Twitch Studio was discontinued in May 2024.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:twitch:twitch_studio:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:twitch:twitch_studio:*:*:*:*:*:*:*:*range: <=0.114.8
- (no CPE)range: <=0.114.8
Patches
Vulnerability mechanics
References
4- www.iru.com/blog/twitch-privileged-helpernvdExploitThird Party Advisory
- www.vulncheck.com/advisories/twitch-studio-launcherhelper-xpc-missing-authorization-to-root-file-writenvdThird Party Advisory
- help.twitch.tv/s/article/recommended-software-for-broadcastingnvdProduct
- help.twitch.tv/s/topic/0TO3a000000kZfYGAU/twitch-studionvdProduct
News mentions
0No linked articles in our index yet.