A vulnerability was identified in the XPC services of Fantastical. The services failed to implement proper client authorization checks in its listener:shouldAcceptNewConnection method, unconditionally accepting requests from any local process. As a result, any local, unprivileged process could connect to the XPC service and access its methods.
This issue has been resolved in version 4.0.16.
This issue has been resolved in version 4.0.16.
Metrics
Affected Vendors & Products
References
History
Thu, 07 Aug 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Flexibits
Flexibits fantastical |
|
Vendors & Products |
Flexibits
Flexibits fantastical |
Thu, 07 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 07 Aug 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was identified in the XPC services of Fantastical. The services failed to implement proper client authorization checks in its listener:shouldAcceptNewConnection method, unconditionally accepting requests from any local process. As a result, any local, unprivileged process could connect to the XPC service and access its methods. This issue has been resolved in version 4.0.16. | |
Title | Incorrect Authorization of XPC Service in Fantastical.app | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-08-07T13:27:42.989Z
Reserved: 2025-08-04T11:48:41.791Z
Link: CVE-2025-8533

Updated: 2025-08-07T13:27:37.942Z

Status : Awaiting Analysis
Published: 2025-08-07T10:15:38.410
Modified: 2025-08-07T21:26:37.453
Link: CVE-2025-8533

No data.

Updated: 2025-08-07T22:01:47Z