Intelligence
Advisories, writeups, and field notes.
Everything we've cleared for public reading — root-cause analysis, disclosed advisories, and notes from the work.
tags
research 3
macOS 3
CVE 3
macos 2
privacy 2
MacOS 1
Bluetoothd 1
zero-click 1
edge 1
microsoft-to-do 1
code-signing 1
privilege-escalation 1
dyld 1
oneauth 1
credential-theft 1
sandbox 1
filevault 1
authd 1
identity spoofing 1
Open WebUI 1
header injection 1
Lockdown Mode 1
App Sandbox 1
bounty 1
hackerone 1
disclosure 1
path traversal 1
Python 1
OSINT 1
Zen Browser 1
update signing 1
MAR 1
CVE-2026-59224 — Open WebUI Terminal Proxy Forwards Spoofable Identity
Open WebUI's terminal proxy passes X-User-Id to upstream services as a raw header with no cryptographic binding. If anything else can reach the upstream, it can impersonate any user.
CVE-2026-42866 — Path Traversal in Tookie OSINT
A path traversal in Tookie OSINT's output writers let a crafted username write scan results to arbitrary filesystem paths. High severity, fixed after disclosure.
CVE-2026-41431 — Zen Browser Shipped Without Update Signature Verification
The Zen Browser MAR updater shipped without signature verification enabled. A missing build variable meant the client accepted unsigned updates. Fixed in 5 days.
No reports match your filter.