This issue has been resolved in version 4.0.16.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23914 | A vulnerability was identified in the XPC services of Fantastical. The services failed to implement proper client authorization checks in its listener:shouldAcceptNewConnection method, unconditionally accepting requests from any local process. As a result, any local, unprivileged process could connect to the XPC service and access its methods. This issue has been resolved in version 4.0.16. |
Thu, 07 Aug 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flexibits
Flexibits fantastical |
|
| Vendors & Products |
Flexibits
Flexibits fantastical |
Thu, 07 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 07 Aug 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in the XPC services of Fantastical. The services failed to implement proper client authorization checks in its listener:shouldAcceptNewConnection method, unconditionally accepting requests from any local process. As a result, any local, unprivileged process could connect to the XPC service and access its methods. This issue has been resolved in version 4.0.16. | |
| Title | Incorrect Authorization of XPC Service in Fantastical.app | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-08-07T13:27:42.989Z
Reserved: 2025-08-04T11:48:41.791Z
Link: CVE-2025-8533
Updated: 2025-08-07T13:27:37.942Z
Status : Deferred
Published: 2025-08-07T10:15:38.410
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-8533
No data.
OpenCVE Enrichment
Updated: 2025-08-07T22:01:47Z
EUVD