Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.tool2. The helper validates connecting XPC clients by obtaining the client's process identifier and using it to retrieve code-signing information for the process. This PID-based client validation is subject to a time-of-check time-of-use race condition because process identifiers can be reused. A local attacker can exploit PID reuse so that validation is performed against a trusted process instead of the original connecting process. This allows unauthorized access to privileged helper functionality and may lead to local privilege escalation.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://r.sec-consult.com/slate |
|
History
Wed, 10 Jun 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.tool2. The helper validates connecting XPC clients by obtaining the client's process identifier and using it to retrieve code-signing information for the process. This PID-based client validation is subject to a time-of-check time-of-use race condition because process identifiers can be reused. A local attacker can exploit PID reuse so that validation is performed against a trusted process instead of the original connecting process. This allows unauthorized access to privileged helper functionality and may lead to local privilege escalation. | |
| Title | Slate Digital Connect macOS XPC PID validation privilege escalation | |
| Weaknesses | CWE-367 | |
| References |
|
Status: PUBLISHED
Assigner: SEC-VLab
Published:
Updated: 2026-06-10T11:49:10.839Z
Reserved: 2026-01-21T11:29:19.853Z
Link: CVE-2026-24067
No data.
Status : Received
Published: 2026-06-10T12:16:25.340
Modified: 2026-06-10T12:16:25.340
Link: CVE-2026-24067
No data.
OpenCVE Enrichment
Updated: 2026-06-10T13:30:06Z