
VOCALOID6 Editor 6.13.2 security update addresses two vulnerabilities
Summary
Yamaha released VOCALOID6 Editor 6.13.2 to address two security vulnerabilities affecting versions 6.13.1 and earlier. Users should install the update through the official download channel.
Yamaha has released VOCALOID6 Editor Updater version 6.13.2, which addresses the vulnerabilities listed as JVNVU#90210212.
According to JPCERT/CC’s advisory, VOCALOID6 Editor versions 6.13.1 and earlier are affected. The advisory identifies CVE-2026-76131, involving hard-coded credentials that could allow an attacker to impersonate a legitimate editor and access Yamaha activation and content servers, and CVE-2026-76137, a local named-pipe issue through which a process running under the same user account could escalate privileges.
Users should update to version 6.13.2 through the official VOCALOID download channel. On macOS, Yamaha instructs users to mount the downloaded DMG and run the included PKG; on Windows, users should extract the ZIP and run the EXE.
Yamaha also notes that VOCALOID6 Editor 6.3.0 or later must be installed before updating VOCALOID6 Voicebanks 6.3.0 or later. For VOCALOID AU and VOCALOID Bridge in Logic Pro X or GarageBand on Apple Silicon Macs, the host application must be opened using Rosetta.
Read the original