CVE-2026-24067 Details
Description
Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.tool2. The helper validates connecting XPC clients by obtaining the client's process identifier and using it to retrieve code-signing information for the process. This PID-based client validation is subject to a time-of-check time-of-use race condition because process identifiers can be reused. A local attacker can exploit PID reuse so that validation is performed against a trusted process instead of the original connecting process. This allows unauthorized access to privileged helper functionality and may lead to local privilege escalation.
A local privilege escalation vulnerability has been identified in Slate Digital Connect version 1.37.0 for macOS. The issue arises from inadequate validation of XPC clients by the privileged helper tool 'com.slatedigital.connect.privileged.helper.tool', which is installed in '/Library/PrivilegedHelperTools'. The helper tool exposes an XPC service that validates connecting clients based on their process identifiers (PIDs). However, this PID-based validation is flawed, as PIDs can be reused, allowing a local attacker to manipulate the validation process and gain unauthorized access to privileged functionalities, potentially leading to elevated rights.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 10, 2026CISA-ADP
Assessed Jun 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec-consult.com/vulnerability-lab/advisory/local-privilege-escalation-in-slate-digital-connect/ | CISA-ADP | |
| https://r.sec-consult.com/slate | SEC Consult Vulnerability Lab | BundleExploitRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition | SEC Consult Vulnerability Lab |
Affected Products
| Product | Versions |
|---|---|
| Slate Digital Connect | 1.37.0 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | SEC Consult Vulnerability Lab |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 10, 2026 | CVE Modified | CISA-ADP |
| Jun 10, 2026 | New CVE Received | SEC Consult Vulnerability Lab |
Volerion