Description
NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing attacker-controlled command and NSBundlePath values.This issue affects NoSleep: 1.5.1.
Published: 2026-08-20
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NoSleep 1.5.1 allows a privileged XPC Mach service to accept raw dictionary messages containing attacker‑controlled command and NSBundlePath values. Because the service runs with elevated privileges, an attacker can exploit this flaw to read files owned by the root user, resulting in confidential data disclosure. This vulnerability is a missing authorization check for a privileged resource (CWE‑862).

Affected Systems

The affected product is the NoSleep application version 1.5.1 running on macOS. Only this specific version is known to be vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. Based on the description, the likely attack vector is a local privileged XPC service; a local user or process that can communicate with the mach service could send crafted messages to read root‑owned files. The exploitability requires the XPC helper to be running with root privileges and the absence of authorization checks. Because the service operates locally, the risk is limited to local footholds, but the impact of exposed root data is significant.

Generated by OpenCVE AI on August 21, 2026 at 01:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update NoSleep to the latest version that addresses the privileged XPC service vulnerability.
  • If an update is not immediately available, disable or remove the privileged XPC Mach service until the vendor releases a fix.
  • Verify that the XPC service includes proper authorization checks and enforce least privilege when granting access to the service.

Generated by OpenCVE AI on August 21, 2026 at 01:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing attacker-controlled command and NSBundlePath values.This issue affects NoSleep: 1.5.1.
Title NoSleep 1.5.1 - Unauthorized disclosure of root-owned files through privileged XPC helper
First Time appeared Nosleep
Nosleep nosleep
Weaknesses CWE-862
CPEs cpe:2.3:a:nosleep:nosleep:1.5.1:*:macos:*:*:*:*:*
Vendors & Products Nosleep
Nosleep nosleep
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published:

Updated: 2026-08-25T19:11:30.734Z

Reserved: 2026-08-13T15:38:11.224Z

Link: CVE-2026-19755

cve-icon Vulnrichment

Updated: 2026-08-25T19:11:16.539Z

cve-icon NVD

Status : Deferred

Published: 2026-08-20T21:17:06.283

Modified: 2026-08-28T15:31:31.210

Link: CVE-2026-19755

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:08:33Z

Weaknesses