CVE-2026-24071Disclosure(native-instruments / native_access)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

It was found that the XPC service offered by the privileged helper of Native Access uses the PID of the connecting client to verify its code signature. This is considered insecure and can be exploited by PID reuse attacks. The connection handler function uses _xpc_connection_get_pid(arg2) as argument for the hasValidSignature function. This value can not be trusted since it is vulnerable to PID reuse attacks.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • native_access

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
native_access

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-02: 1Technical Details · 2026-02-02: 102-02
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-24071 - Critical It was found that the XPC service offered by the privileged helper of Native Access uses the PID of the connecting client to verify its code signature. This is considered insecure and ca... https://www.thehackerwire.com/vulnerability/CVE-2026-24071/ https://t.co/98ATHsltnf

    Post summary

    A critical vulnerability (CVE-2026-24071) was disclosed in Native Access, where the privileged helper’s XPC service incorrectly verifies code signatures using the client PID, exposing a security flaw.

    0000089
    113 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnative-instrumentsnative_access---

Explore more