CVE-2025-8533

A vulnerability was identified in the XPC services of Fantastical. The services failed to implement proper client authorization checks in its listener:shouldAcceptNewConnection method, unconditionally accepting requests from any local process. As a result, any local, unprivileged process could connect to the XPC service and access its methods. This issue has been resolved in version 4.0.16.
CVSS

No CVSS.

Configurations

No configuration.

History

07 Aug 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-07 10:15

Updated : 2025-08-07 21:26


NVD link : CVE-2025-8533

Mitre link : CVE-2025-8533

CVE.ORG link : CVE-2025-8533


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization