CVE-2024-14032
EUVD-2024-5553506.04.2026, 16:16
Twitch Studio version 0.114.8 and prior contain a privilege escalation vulnerability in its privileged helper tool that allows local attackers to execute arbitrary code as root by exploiting an unprotected XPC service. Attackers can invoke the installFromPath:toPath:withReply: method to overwrite system files and privileged binaries, achieving full system compromise. Twitch Studio was discontinued in May 2024.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| twitch | twitch_studio | 𝑥 ≤ 0.114.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References