CVE-2026-19755: NoSleep 1.5.1 - Unauthorized disclosure of root-owned files through privileged XPC helper
Published Aug 20, 2026
·Updated
NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing attacker-controlled command and NSBundlePath values.This issue affects NoSleep: 1.5.1.
Affected Software
1 affected component
NoSleep NoSleep=1.5.1
Event History
Aug 20, 2026
CVE Published
via MITRE·08:26 PM
Data Sourced
via MITRE·08:26 PM
DescriptionWeakness
Frequently Asked Questions
1
Which version is known to be affected?
The affected version identified is NoSleep 1.5.1.
2
What inputs does an attacker control when interacting with the vulnerable service?
The privileged XPC Mach service accepts raw dictionary messages containing attacker-controlled command and NSBundlePath values.