FARPSEC

Intelligence

Advisories, writeups, and field notes.

Everything we've cleared for public reading — root-cause analysis, disclosed advisories, and notes from the work.

2026.10.04 Post 7 min

0-Click Bluetooth Overflow in Apple's Root Daemon: Finding Two Memory Corruption Bugs in bluetoothd

On September 14, 2026, Apple shipped iOS 27, tvOS 27, watchOS 27, and visionOS 27. In the security advisories for all four releases, under CoreBluetooth - LE Additional Recognition:

> "We would like to acknowledge ... Maliq Barnard ... for their assistance."

This is the story behind that credit — two memory corruption bugs in Apple's Bluetooth daemon, found through systematic binary analysis and proven in the live root process.

MacOSBluetoothdzero-click · Maliq Barnard
2026.10.04 Post CVE-2026-69446 5 min

CVE-2026-69446 — Microsoft Edge and To Do macOS DYLD Code Injection to Credential Theft

Two Microsoft macOS apps shipped without library-validation, allowing DYLD_INSERT_LIBRARIES injection. EdgeUpdater escalates to root through an unsanitized install script. To Do goes deeper — the injected code inherits sandbox entitlements and can call the full OneAuth/MSAL framework to steal OAuth tokens across every Microsoft app on the Mac.

macosedgemicrosoft-to-docode-signingprivilege-escalationdyldoneauthcredential-theft · Maliq Barnard
2026.08.27 Post 3 min

authd Handed FileVault Key Material to Any Sandboxed App

A core macOS authorization daemon returned the pre-login user database, including password-wrapped FileVault keys, to any local process, sandboxed apps included, with no entitlement, TCC prompt, or authorization check. Fixed in macOS 26.5.

researchmacOSsandboxfilevaultauthd · Maliq Barnard
2026.08.21 Post 4 min

NordVPN for macOS Stored Your Real IP and GPS in Plaintext

A VPN that cached the exact IP, coordinates, ISP and location it exists to hide, in world-readable files at rest, with no sandbox. Reported to Nord Security, HackerOne #3640402.

researchmacOSprivacy · Maliq Barnard
2026.07.08 Post CVE-2026-59224 3 min

CVE-2026-59224 — Open WebUI Terminal Proxy Forwards Spoofable Identity

Open WebUI's terminal proxy passes X-User-Id to upstream services as a raw header with no cryptographic binding. If anything else can reach the upstream, it can impersonate any user.

CVEidentity spoofingOpen WebUIheader injection · Maliq Barnard
2026.05.19 Post 6 min

Any macOS App Can Tell If You're Using Lockdown Mode

A single syscall from inside the App Sandbox reveals whether Lockdown Mode is enabled. No permissions, no prompt. Any app knows your security posture and you'll never know it asked. Apple says this is expected behavior.

researchmacOSprivacyLockdown ModeApp Sandbox · Maliq Barnard
2026.05.13 Post 1 min

First Bounty Awarded

FARPSEC receives its first paid vulnerability bounty through coordinated disclosure on HackerOne. Details after remediation.

bountyhackeronemacosdisclosure · Maliq Barnard
2026.05.12 Post CVE-2026-42866 2 min

CVE-2026-42866 — Path Traversal in Tookie OSINT

A path traversal in Tookie OSINT's output writers let a crafted username write scan results to arbitrary filesystem paths. High severity, fixed after disclosure.

CVEpath traversalPythonOSINT · Maliq Barnard
2026.04.24 Post CVE-2026-41431 2 min

CVE-2026-41431 — Zen Browser Shipped Without Update Signature Verification

The Zen Browser MAR updater shipped without signature verification enabled. A missing build variable meant the client accepted unsigned updates. Fixed in 5 days.

CVEZen Browserupdate signingMAR · Maliq Barnard