CVE Feed

    Dashboard / CVE / CVE-2026-24071

    CVE-2026-24071

    It was found that the XPC service offered by the privileged helper of Native Access uses the PID of the connecting client to verify its code signature. This is considered insecure and can be exploited by PID reuse attacks. The connection handler function uses _xpc_connection_get_pid(arg2) as argument for the hasValidSignature function. This value can not be trusted since it is vulnerable to PID reuse attacks.

    Published:Feb 2, 2026
    Last Modified:Apr 18, 2026
    EPS:Feb 2, 2026
    EPSS Score:0.00005
    CVSS Score:7.8

    Affected Products

    Vendor
    Native-instruments
    Product
    Native Access
    Vendor
    Native Instruments
    Product
    Native Access

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High