FARPSEC

Intelligence

Advisories, writeups, and field notes.

Everything we've cleared for public reading — root-cause analysis, disclosed advisories, and notes from the work.

2026.10.04 Post 7 min

0-Click Bluetooth Overflow in Apple's Root Daemon: Finding Two Memory Corruption Bugs in bluetoothd

On September 14, 2026, Apple shipped iOS 27, tvOS 27, watchOS 27, and visionOS 27. In the security advisories for all four releases, under CoreBluetooth - LE Additional Recognition:

> "We would like to acknowledge ... Maliq Barnard ... for their assistance."

This is the story behind that credit — two memory corruption bugs in Apple's Bluetooth daemon, found through systematic binary analysis and proven in the live root process.

MacOSBluetoothdzero-click · Maliq Barnard
2026.10.04 Post CVE-2026-69446 5 min

CVE-2026-69446 — Microsoft Edge and To Do macOS DYLD Code Injection to Credential Theft

Two Microsoft macOS apps shipped without library-validation, allowing DYLD_INSERT_LIBRARIES injection. EdgeUpdater escalates to root through an unsanitized install script. To Do goes deeper — the injected code inherits sandbox entitlements and can call the full OneAuth/MSAL framework to steal OAuth tokens across every Microsoft app on the Mac.

macosedgemicrosoft-to-docode-signingprivilege-escalationdyldoneauthcredential-theft · Maliq Barnard
2026.08.27 Post 3 min

authd Handed FileVault Key Material to Any Sandboxed App

A core macOS authorization daemon returned the pre-login user database, including password-wrapped FileVault keys, to any local process, sandboxed apps included, with no entitlement, TCC prompt, or authorization check. Fixed in macOS 26.5.

researchmacOSsandboxfilevaultauthd · Maliq Barnard
2026.08.21 Post 4 min

NordVPN for macOS Stored Your Real IP and GPS in Plaintext

A VPN that cached the exact IP, coordinates, ISP and location it exists to hide, in world-readable files at rest, with no sandbox. Reported to Nord Security, HackerOne #3640402.

researchmacOSprivacy · Maliq Barnard
2026.05.19 Post 6 min

Any macOS App Can Tell If You're Using Lockdown Mode

A single syscall from inside the App Sandbox reveals whether Lockdown Mode is enabled. No permissions, no prompt. Any app knows your security posture and you'll never know it asked. Apple says this is expected behavior.

researchmacOSprivacyLockdown ModeApp Sandbox · Maliq Barnard
2026.05.13 Post 1 min

First Bounty Awarded

FARPSEC receives its first paid vulnerability bounty through coordinated disclosure on HackerOne. Details after remediation.

bountyhackeronemacosdisclosure · Maliq Barnard