CVE-2026-28403 affects Textream, a macOS teleprompter app, prior to version 1.5.1. The vulnerability stems from the DirectorServer WebSocket server accepting connections from any origin without proper validation, allowing a malicious webpage to silently connect and send arbitrary commands. This high-severity flaw (CVSS 8.6) permits full remote control of the teleprompter content, with potential for low impact on confidentiality and availability, but high impact on integrity. There is no evidence of active exploitation, publicly available exploit code, or inclusion in the KEV catalog, though it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.1CPE matchmatch criteria | cpe:2.3:a:fka:textream:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.