Vulnerability research collective
We find the bug before someone worse does.
FARPSEC reverse-engineers the software the world runs on — operating systems, browsers, the daemons nobody reads — and reports what we find with a repro anyone can follow.
- Vendor firstDetail waits until a fix ships or the clock runs out.
- Root causeNot a screenshot of a crash with no stack.
- Five-minute reproDone when someone else can reproduce it.
Latest intelligence
All reportsMongoDB Compass RCE — One Click from Code Execution via Database Name Injection
MongoDB Compass interpolated database names directly into JavaScript evaluated by a mongosh worker with full require() access. A database named with a child_process payload executes arbitrary commands on the analyst's machine the moment they click Open MongoDB Shell. $3,000 bounty, HackerOne #3756002.
0-Click Bluetooth Overflow in Apple's Root Daemon: Finding Two Memory Corruption Bugs in bluetoothd
On September 14, 2026, Apple shipped iOS 27, tvOS 27, watchOS 27, and visionOS 27. In the security advisories for all four releases, under CoreBluetooth - LE Additional Recognition:
> "We would like to acknowledge ... Maliq Barnard ... for their assistance."
This is the story behind that credit — two memory corruption bugs in Apple's Bluetooth daemon, found through systematic binary analysis and proven in the live root process.
CVE-2026-69446 — Microsoft Edge and To Do macOS DYLD Code Injection to Credential Theft
Two Microsoft macOS apps shipped without library-validation, allowing DYLD_INSERT_LIBRARIES injection. EdgeUpdater escalates to root through an unsanitized install script. To Do goes deeper — the injected code inherits sandbox entitlements and can call the full OneAuth/MSAL framework to steal OAuth tokens across every Microsoft app on the Mac.
authd Handed FileVault Key Material to Any Sandboxed App
A core macOS authorization daemon returned the pre-login user database, including password-wrapped FileVault keys, to any local process, sandboxed apps included, with no entitlement, TCC prompt, or authorization check. Fixed in macOS 26.5.
NordVPN for macOS Stored Your Real IP and GPS in Plaintext
A VPN that cached the exact IP, coordinates, ISP and location it exists to hide, in world-readable files at rest, with no sandbox. Reported to Nord Security, HackerOne #3640402.
How we work
Every finding ships with a root cause, a minimal reproduction, and the exact conditions it needs. No screenshots of a crash with no stack. No "trust me." A report is finished when someone else can reproduce it in five minutes.
Disclosure
We report to the vendor first and hold detail until a fix ships or the clock runs out. What reaches this site has already been through that.