VYPR

Waves Central

by Waves

CVEs (2)

  • CVE-2026-24065HigJun 9, 2026
    risk 0.53cvss 8.1epss 0.00

    Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability in the privileged helper service. The helper validates connecting XPC clients using the client process identifier (PID) to verify code-signing identity. Because process…

  • CVE-2026-24064HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability. A trusted XPC client component included with the product is signed with hardened runtime entitlements that permit dynamic library injection. A local attacker can set the…