FARPSEC

Vulnerability research collective

We find the bug before someone worse does.

FARPSEC reverse-engineers the software the world runs on — operating systems, browsers, the daemons nobody reads — and reports what we find with a repro anyone can follow.

  • Vendor firstDetail waits until a fix ships or the clock runs out.
  • Root causeNot a screenshot of a crash with no stack.
  • Five-minute reproDone when someone else can reproduce it.

Latest intelligence

All reports
2026.10.05 Post

MongoDB Compass RCE — One Click from Code Execution via Database Name Injection

MongoDB Compass interpolated database names directly into JavaScript evaluated by a mongosh worker with full require() access. A database named with a child_process payload executes arbitrary commands on the analyst's machine the moment they click Open MongoDB Shell. $3,000 bounty, HackerOne #3756002.

2026.10.04 Post

0-Click Bluetooth Overflow in Apple's Root Daemon: Finding Two Memory Corruption Bugs in bluetoothd

On September 14, 2026, Apple shipped iOS 27, tvOS 27, watchOS 27, and visionOS 27. In the security advisories for all four releases, under CoreBluetooth - LE Additional Recognition:

> "We would like to acknowledge ... Maliq Barnard ... for their assistance."

This is the story behind that credit — two memory corruption bugs in Apple's Bluetooth daemon, found through systematic binary analysis and proven in the live root process.

2026.10.04 Post CVE-2026-69446

CVE-2026-69446 — Microsoft Edge and To Do macOS DYLD Code Injection to Credential Theft

Two Microsoft macOS apps shipped without library-validation, allowing DYLD_INSERT_LIBRARIES injection. EdgeUpdater escalates to root through an unsanitized install script. To Do goes deeper — the injected code inherits sandbox entitlements and can call the full OneAuth/MSAL framework to steal OAuth tokens across every Microsoft app on the Mac.

2026.08.27 Post

authd Handed FileVault Key Material to Any Sandboxed App

A core macOS authorization daemon returned the pre-login user database, including password-wrapped FileVault keys, to any local process, sandboxed apps included, with no entitlement, TCC prompt, or authorization check. Fixed in macOS 26.5.

2026.08.21 Post

NordVPN for macOS Stored Your Real IP and GPS in Plaintext

A VPN that cached the exact IP, coordinates, ISP and location it exists to hide, in world-readable files at rest, with no sandbox. Reported to Nord Security, HackerOne #3640402.

How we work

Every finding ships with a root cause, a minimal reproduction, and the exact conditions it needs. No screenshots of a crash with no stack. No "trust me." A report is finished when someone else can reproduce it in five minutes.

Disclosure

We report to the vendor first and hold detail until a fix ships or the clock runs out. What reaches this site has already been through that.