CVE-2026-19755: Nosleep

Medium severity, CVSS 6.9. EPSS: 0.1% chance of exploitation in the next 30 days.

NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing attacker-controlled command and NSBundlePath values.This issue affects NoSleep: 1.5.1.

Affected products

  • Nosleep Nosleep: version 1.5.1 only

Published 2026-08-20. Last modified 2026-08-28.