Intelligence
Advisories, writeups, and field notes.
Everything we've cleared for public reading — root-cause analysis, disclosed advisories, and notes from the work.
0-Click Bluetooth Overflow in Apple's Root Daemon: Finding Two Memory Corruption Bugs in bluetoothd
On September 14, 2026, Apple shipped iOS 27, tvOS 27, watchOS 27, and visionOS 27. In the security advisories for all four releases, under CoreBluetooth - LE Additional Recognition:
> "We would like to acknowledge ... Maliq Barnard ... for their assistance."
This is the story behind that credit — two memory corruption bugs in Apple's Bluetooth daemon, found through systematic binary analysis and proven in the live root process.
CVE-2026-69446 — Microsoft Edge and To Do macOS DYLD Code Injection to Credential Theft
Two Microsoft macOS apps shipped without library-validation, allowing DYLD_INSERT_LIBRARIES injection. EdgeUpdater escalates to root through an unsanitized install script. To Do goes deeper — the injected code inherits sandbox entitlements and can call the full OneAuth/MSAL framework to steal OAuth tokens across every Microsoft app on the Mac.
authd Handed FileVault Key Material to Any Sandboxed App
A core macOS authorization daemon returned the pre-login user database, including password-wrapped FileVault keys, to any local process, sandboxed apps included, with no entitlement, TCC prompt, or authorization check. Fixed in macOS 26.5.
NordVPN for macOS Stored Your Real IP and GPS in Plaintext
A VPN that cached the exact IP, coordinates, ISP and location it exists to hide, in world-readable files at rest, with no sandbox. Reported to Nord Security, HackerOne #3640402.
CVE-2026-59224 — Open WebUI Terminal Proxy Forwards Spoofable Identity
Open WebUI's terminal proxy passes X-User-Id to upstream services as a raw header with no cryptographic binding. If anything else can reach the upstream, it can impersonate any user.
Any macOS App Can Tell If You're Using Lockdown Mode
A single syscall from inside the App Sandbox reveals whether Lockdown Mode is enabled. No permissions, no prompt. Any app knows your security posture and you'll never know it asked. Apple says this is expected behavior.
First Bounty Awarded
FARPSEC receives its first paid vulnerability bounty through coordinated disclosure on HackerOne. Details after remediation.
CVE-2026-42866 — Path Traversal in Tookie OSINT
A path traversal in Tookie OSINT's output writers let a crafted username write scan results to arbitrary filesystem paths. High severity, fixed after disclosure.
CVE-2026-41431 — Zen Browser Shipped Without Update Signature Verification
The Zen Browser MAR updater shipped without signature verification enabled. A missing build variable meant the client accepted unsigned updates. Fixed in 5 days.
No reports match your filter.