We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
A vulnerability was identified in the XPC services of Fantastical. The services failed to implement proper client authorization checks in its listener:shouldAcceptNewConnection method, unconditionally accepting requests from any local process. As a result, any local, unprivileged process could connect to the XPC service and access its methods. This issue has been resolved in version 4.0.16.
Reserved 2025-08-04 | Published 2025-08-07 | Updated 2025-08-07 | Assigner CERT-PLCWE-863 Incorrect Authorization
Karol Mazurek - Afine Team
Sławomir Zakrzewski - Afine Team
cert.pl/en/posts/2025/08/CVE-2025-8533
flexibits.com/fantastical
Support options