🔐 CVE Alert

CVE-2026-19755

UNKNOWN 0.0

NoSleep 1.5.1 - Unauthorized disclosure of root-owned files through privileged XPC helper

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing attacker-controlled command and NSBundlePath values.This issue affects NoSleep: 1.5.1.

CWE CWE-862
Vendor nosleep
Product nosleep
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for nosleep nosleep

Be the first to know when new unknown vulnerabilities affecting nosleep nosleep are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

NoSleep / NoSleep
1.5.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
fluidattacks.com: https://fluidattacks.com/advisories/iggy github.com: https://github.com/integralpro/nosleep/

Credits

Oscar Uribe