PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-24066 Slate Digital LLC CVE debrief

CVE-2026-24066 is a HIGH-severity vulnerability in Slate Digital Connect 1.37.0 for macOS. The vulnerability is caused by a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes an XPC service that can be accessed by a local attacker using a self-signed certificate with a specific organizational unit value. This allows unauthorized access to privileged helper functionality and may lead to local privilege escalation.

Vendor
Slate Digital LLC
Product
Slate Digital Connect
CVSS
HIGH 8.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-10
Original CVE updated
2026-06-10
Advisory published
2026-06-10
Advisory updated
2026-06-10

Who should care

Users of Slate Digital Connect 1.37.0 for macOS should apply the necessary patches to prevent local privilege escalation.

Technical summary

The Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.tool2. The helper validates connecting XPC clients by checking only the subject.OU value of the client's signing certificate and does not verify that the certificate chains to a trusted code-signing authority.

Defensive priority

HIGH

Recommended defensive actions

  • Apply patches or updates provided by the vendor to fix the vulnerability.
  • Use secure coding practices to verify the certificate chain to a trusted code-signing authority.

Evidence notes

The vulnerability was reported by Sec Consult.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-24066 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-24066

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-24066 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-24066

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://r.sec-consult.com/slate

    551230f0-3615-47bd-b7cc-93e92e730bbf

  • Source reference

    Unverified legacy reference

    URL: https://sec-consult.com/vulnerability-lab/advisory/local-privilege-escalation-in-slate-digital-connect/

    134c704f-9b21-4f2e-91b3-4a467353bcc0

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.