CVE-2025-8533

A vulnerability was identified in the XPC services of Fantastical. The services failed to implement proper client authorization checks in its listener:shouldAcceptNewConnection method, unconditionally accepting requests from any local process. As a result, any local, unprivileged process could connect to the XPC service and access its methods. This issue has been resolved in version 4.0.16.
CVSS

No CVSS.

Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Se identificó una vulnerabilidad en los servicios XPC de Fantastical. Estos servicios no implementaban las comprobaciones de autorización de cliente adecuadas en su método listener:shouldAcceptNewConnection, aceptando incondicionalmente las solicitudes de cualquier proceso local. Como resultado, cualquier proceso local sin privilegios podía conectarse al servicio XPC y acceder a sus métodos. Este problema se ha resuelto en la versión 4.0.16.

07 Aug 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-07 10:15

Updated : 2026-04-15 00:35


NVD link : CVE-2025-8533

Mitre link : CVE-2025-8533

CVE.ORG link : CVE-2025-8533


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization