CVE-2024-14032Disclosure(twitch / twitch_studio)

LOWCVSS 8.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Twitch Studio version 0.114.8 and prior contain a privilege escalation vulnerability in its privileged helper tool that allows local attackers to execute arbitrary code as root by exploiting an unprotected XPC service. Attackers can invoke the installFromPath:toPath:withReply: method to overwrite system files and privileged binaries, achieving full system compromise. Twitch Studio was discontinued in May 2024.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • twitch_studio

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
twitch_studio

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-06: 2Technical Details · 2026-04-06: 204-06
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2024-14032 Twitch Studio version 0.114.8 and prior contain a privilege escalation vulnerability in its privileged helper tool that allows local attackers to execute arbitrary co… https://www.cve.org/CVERecord?id=CVE-2024-14032 ----- Traducción: CVE-2024-14032 Twi… http://infoflow.cloud`

    Post summary

    CVE‑2024‑14032 reveals a local privilege escalation flaw in Twitch Studio’s privileged helper tool that can let attackers run arbitrary code, though no PoC, exploit code, or active exploitation reports are mentioned.

    0000045
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2024-14032 Twitch Studio version 0.114.8 and prior contain a privilege escalation vulnerability in its privileged helper tool that allows local attackers to execute arbitrary co… https://www.cve.org/CVERecord?id=CVE-2024-14032

    Post summary

    CVE‑2024‑14032 is a privilege‑escalation flaw in Twitch Studio’s privileged helper tool that permits local attackers to execute arbitrary code.

    00000187
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptwitchtwitch_studio---

Explore more