Early access: the directory is still filling out, and every rating here is a reported experience.

Intelligence

Security research from FARPSEC

Advisories, root-cause analysis, and vulnerability writeups — pulled live from farpsec.xyz.

Powered by FARPSEC research

Feed

9 published pieces
4 with CVE identifiers
Oct 2026 latest

9 published pieces

2026.10.04 Post

0-Click Bluetooth Overflow in Apple's Root Daemon: Finding Two Memory Corruption Bugs in bluetoothd

On September 14, 2026, Apple shipped iOS 27, tvOS 27, watchOS 27, and visionOS 27. In the security advisories for all four releases, under CoreBluetooth - LE Additional Recognition: > *"We would like to acknowledge .....

MacOS Bluetoothd zero-click
Maliq Barnard Read on FARPSEC →
2026.10.04 Post CVE-2026-69446

CVE-2026-69446 — Microsoft Edge and To Do macOS DYLD Code Injection to Credential Theft

Two Microsoft macOS apps shipped without library-validation, allowing DYLD_INSERT_LIBRARIES injection. EdgeUpdater escalates to root through an unsanitized install script. To Do goes deeper — the injected code inherits s...

macos edge microsoft-to-do code-signing privilege-escalation
Maliq Barnard Read on FARPSEC →
2026.08.27 Post

authd Handed FileVault Key Material to Any Sandboxed App

A core macOS authorization daemon returned the pre-login user database, including password-wrapped FileVault keys, to any local process, sandboxed apps included, with no entitlement, TCC prompt, or authorization check. F...

research macOS sandbox filevault authd
Maliq Barnard Read on FARPSEC →
2026.08.21 Post

NordVPN for macOS Stored Your Real IP and GPS in Plaintext

A VPN that cached the exact IP, coordinates, ISP and location it exists to hide, in world-readable files at rest, with no sandbox. Reported to Nord Security, HackerOne #3640402.

research macOS privacy
Maliq Barnard Read on FARPSEC →
2026.07.08 Post CVE-2026-59224

CVE-2026-59224 — Open WebUI Terminal Proxy Forwards Spoofable Identity

Open WebUI's terminal proxy passes X-User-Id to upstream services as a raw header with no cryptographic binding. If anything else can reach the upstream, it can impersonate any user.

CVE identity spoofing Open WebUI header injection
Maliq Barnard Read on FARPSEC →
2026.05.19 Post

Any macOS App Can Tell If You're Using Lockdown Mode

A single syscall from inside the App Sandbox reveals whether Lockdown Mode is enabled. No permissions, no prompt. Any app knows your security posture and you'll never know it asked. Apple says this is expected behavior.

research macOS privacy Lockdown Mode App Sandbox
Maliq Barnard Read on FARPSEC →
2026.05.13 Post

First Bounty Awarded

FARPSEC receives its first paid vulnerability bounty through coordinated disclosure on HackerOne. Details after remediation.

bounty hackerone macos disclosure
Maliq Barnard Read on FARPSEC →
2026.05.12 Post CVE-2026-42866

CVE-2026-42866 — Path Traversal in Tookie OSINT

A path traversal in Tookie OSINT's output writers let a crafted username write scan results to arbitrary filesystem paths. High severity, fixed after disclosure.

CVE path traversal Python OSINT
Maliq Barnard Read on FARPSEC →
2026.04.24 Post CVE-2026-41431

CVE-2026-41431 — Zen Browser Shipped Without Update Signature Verification

The Zen Browser MAR updater shipped without signature verification enabled. A missing build variable meant the client accepted unsigned updates. Fixed in 5 days.

CVE Zen Browser update signing MAR
Maliq Barnard Read on FARPSEC →