Intelligence
Advisories, writeups, and field notes.
Everything we've cleared for public reading — root-cause analysis, disclosed advisories, and notes from the work.
tags
research 3
macOS 3
CVE 3
macos 2
privacy 2
MacOS 1
Bluetoothd 1
zero-click 1
edge 1
microsoft-to-do 1
code-signing 1
privilege-escalation 1
dyld 1
oneauth 1
credential-theft 1
sandbox 1
filevault 1
authd 1
identity spoofing 1
Open WebUI 1
header injection 1
Lockdown Mode 1
App Sandbox 1
bounty 1
hackerone 1
disclosure 1
path traversal 1
Python 1
OSINT 1
Zen Browser 1
update signing 1
MAR 1
NordVPN for macOS Stored Your Real IP and GPS in Plaintext
A VPN that cached the exact IP, coordinates, ISP and location it exists to hide, in world-readable files at rest, with no sandbox. Reported to Nord Security, HackerOne #3640402.
Any macOS App Can Tell If You're Using Lockdown Mode
A single syscall from inside the App Sandbox reveals whether Lockdown Mode is enabled. No permissions, no prompt. Any app knows your security posture and you'll never know it asked. Apple says this is expected behavior.
No reports match your filter.