Flexibits Fantastical Incorrect Authorization Vulnerability in XPC Services

Vulnerability

A vulnerability exists in the XPC services of Flexibits Fantastical, all versions prior to 4.0.16. The issue arises from inadequate client authorization checks in the 'listener:shouldAcceptNewConnection' method, which allows any local, unprivileged process to connect to the XPC service and access its methods. This flaw could be exploited by any local process without special privileges.

Impact

Exploitation of this vulnerability allows any local, unprivileged process to connect to the XPC service of Fantastical and invoke its methods, potentially leading to unauthorized access or manipulation of data within the application.

Remediation

Users can upgrade to Fantastical version 4.0.16 or later to address this vulnerability.

Added: Aug 7, 2025, 10:17 AM
Updated: Aug 7, 2025, 10:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
4.7
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.