CVE-2026-24066CWE-296

Slate Digital Connect macOS XPC certificate validation privilege escalation

High · published June 10, 2026

CVSS v3.1
8.4
EPSS
0%
Percentile
2.2
In the wild
Unconfirmed
What it is

Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.tool2. The helper validates connecting XPC clients by checking only the subject.OU value of the client's signing certificate and does not verify that the certificate chains to a trusted code-signing authority. A local attacker can sign a malicious client with a self-signed certificate containing the expected organizational unit value and connect to the privileged XPC service. This allows unauthorized access to privileged helper functionality and may lead to local privilege escalation.

The record
Technical detail
CVSS v3.1
8.4 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00122 · 2.2th percentile
Weakness
CWE-296 · Improper Following of a Certificate's Chain of Trust
Published
2026-06-10T11:43Z
EPSS history
Timeline
  • 10 JUN 11:43Z
    Slate Digital Connect macOS XPC certificate validation privilege escalation
    cvelistv5