MEDIUM
Incorrect Authorization of XPC Service in Fantastical.app
Published Aug 7, 2025
6.9
MEDIUMCVSS 4.0
EPSS 0.39%
Description
A vulnerability was identified in the XPC services of Fantastical. The services failed to implement proper client authorization checks in its listener:shouldAcceptNewConnection method, unconditionally accepting requests from any local process. As a result, any local, unprivileged process could connect to the XPC service and access its methods.
This issue has been resolved in version 4.0.16.
Affected products
-
- Version 0StatusaffectedConstraints<4.0.16
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Flexibits | Fantastical | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://cert.pl/en/posts/2025/08/CVE-2025-8533 third-party-advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-23914 Advisory
- https://flexibits.com/fantastical product
| Link | Providers | Tags |
|---|---|---|
| https://cert.pl/en/posts/2025/08/CVE-2025-8533 | third-party-advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-23914 | Advisory | |
| https://flexibits.com/fantastical | product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CERT-PL
Published Aug 7, 2025
Updated Aug 7, 2025
Reserved Aug 4, 2025
Link CVE-2025-8533
CISA Vulnrichment
Updated Aug 7, 2025
ENISA EUVD
EUVD-2025-23914 Assigner CERT-PL
Published Aug 7, 2025
Updated Aug 7, 2025
Exploited since n/a
Link EUVD-2025-23914