CVE-2026-19755
NoSleep 1.5.1 - Unauthorized disclosure of root-owned files through privileged XPC helper
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing attacker-controlled command and NSBundlePath values.This issue affects NoSleep: 1.5.1.
| CWE | CWE-862 |
| Vendor | nosleep |
| Product | nosleep |
| Published | Aug 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for nosleep nosleep
Be the first to know when new unknown vulnerabilities affecting nosleep nosleep are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
NoSleep / NoSleep
1.5.1
References
Credits
Oscar Uribe