Intelligence
Security research from FARPSEC
Advisories, root-cause analysis, and vulnerability writeups — pulled live from farpsec.xyz.
Feed
9 published pieces
0-Click Bluetooth Overflow in Apple's Root Daemon: Finding Two Memory Corruption Bugs in bluetoothd
On September 14, 2026, Apple shipped iOS 27, tvOS 27, watchOS 27, and visionOS 27. In the security advisories for all four releases, under CoreBluetooth - LE Additional Recognition: > *"We would like to acknowledge .....
CVE-2026-69446 — Microsoft Edge and To Do macOS DYLD Code Injection to Credential Theft
Two Microsoft macOS apps shipped without library-validation, allowing DYLD_INSERT_LIBRARIES injection. EdgeUpdater escalates to root through an unsanitized install script. To Do goes deeper — the injected code inherits s...
authd Handed FileVault Key Material to Any Sandboxed App
A core macOS authorization daemon returned the pre-login user database, including password-wrapped FileVault keys, to any local process, sandboxed apps included, with no entitlement, TCC prompt, or authorization check. F...
NordVPN for macOS Stored Your Real IP and GPS in Plaintext
A VPN that cached the exact IP, coordinates, ISP and location it exists to hide, in world-readable files at rest, with no sandbox. Reported to Nord Security, HackerOne #3640402.
CVE-2026-59224 — Open WebUI Terminal Proxy Forwards Spoofable Identity
Open WebUI's terminal proxy passes X-User-Id to upstream services as a raw header with no cryptographic binding. If anything else can reach the upstream, it can impersonate any user.
Any macOS App Can Tell If You're Using Lockdown Mode
A single syscall from inside the App Sandbox reveals whether Lockdown Mode is enabled. No permissions, no prompt. Any app knows your security posture and you'll never know it asked. Apple says this is expected behavior.
First Bounty Awarded
FARPSEC receives its first paid vulnerability bounty through coordinated disclosure on HackerOne. Details after remediation.
CVE-2026-42866 — Path Traversal in Tookie OSINT
A path traversal in Tookie OSINT's output writers let a crafted username write scan results to arbitrary filesystem paths. High severity, fixed after disclosure.
CVE-2026-41431 — Zen Browser Shipped Without Update Signature Verification
The Zen Browser MAR updater shipped without signature verification enabled. A missing build variable meant the client accepted unsigned updates. Fixed in 5 days.