CVE-2026-19755

Summary

NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing attacker-controlled command and NSBundlePath values.This issue affects NoSleep: 1.5.1.

Affected Software

VendorProductVersion RangeStatus
NoSleepNoSleep1.5.1affected

Weaknesses

  • CWE-862: CWE-862 Missing Authorization

References