Back

MEDIUM

Incorrect Authorization of XPC Service in Fantastical.app

Published Aug 7, 2025

Description

A vulnerability was identified in the XPC services of Fantastical. The services failed to implement proper client authorization checks in its listener:shouldAcceptNewConnection method, unconditionally accepting requests from any local process. As a result, any local, unprivileged process could connect to the XPC service and access its methods.

This issue has been resolved in version 4.0.16.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CERT-PL
Published Aug 7, 2025
Updated Aug 7, 2025
Reserved Aug 4, 2025
CISA Vulnrichment
Updated Aug 7, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner CERT-PL
Published Aug 7, 2025
Updated Aug 7, 2025
Exploited since n/a
EUVD-2025-23914