PT-2025-32260 · Flexibits · Fantastical

Karol Mazurek

+1

·

Published

2025-08-07

·

Updated

2025-08-07

·

CVE-2025-8533

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Fantastical versions prior to 4.0.16
Description A flaw exists in the XPC services of Fantastical where proper client authorization checks were not implemented in the listener:shouldAcceptNewConnection method. This allowed any local, unprivileged process to connect to the XPC service and access its methods.
Recommendations Update to version 4.0.16 or later.

Fix

LPE

RCE

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-8533

Affected Products

Fantastical