Junglewise Threat Intelligence

CVE-2026-19755: NoSleep XPC service privilege escalation via command injection

CVE-2026-19755 · Severity: info · CVSS 0 · Published 2026-08-20

Executive brief

NoSleep is a macOS kernel extension that prevents the system from sleeping when the laptop lid is closed. Version 1.5.1 exposes a privileged XPC service that accepts raw dictionary messages with attacker-controlled command and bundle path parameters, allowing an unprivileged user to execute arbitrary commands with root privileges or access sensitive files owned by root.

Technical details

The vulnerability is an insecure XPC inter-process communication flaw in NoSleep 1.5.1. The privileged XPC Mach service accepts raw dictionary messages containing attacker-controlled "command" and "NSBundlePath" values without proper validation or sanitization. An attacker can craft malicious XPC messages to execute arbitrary commands with root privileges or trigger unauthorized disclosure of root-owned files. The attack requires local access to the affected system and does not require authentication beyond standard user privileges. The application is deprecated and no longer maintained as of the advisory date.

Affected products

  • integralpro NoSleep 1.5.1

Timeline

  • 2026-08-20: disclosed

References