interesting20 signals6 min read

Passware shipped physical passcode recovery and protected-data decryption for five Exynos 1280 Galaxy phones, while a systemd 262 and dracut integration gap can leave a TPM-bound LUKS policy eligible after an attacker-controlled root boots.

The phone method is proprietary and model-specific. The boot issue affects specialized configurations, and public evidence stops short of recovering and using the original volume’s key.

Signals20
interesting · Mobile — physical

Passware says it added passcode recovery and decryption for 24 Android phone models.

Affects

Five Samsung Exynos 1280 phones and 19 phones using Unisoc T760, T770 or T820 systems-on-chip, as newly supported by Passware Kit Mobile 2026 v5.

The broader release adds passcode recovery and user-data decryption for 24 Android phone models.

Detail and 4 sources

This remains secondary because the acquisition route, boot-state requirements, and model-by-model operating-system boundary are not public or independently reproduced.

Chain to watch
Obtain a supported locked Android phone.→↓Use Passware’s proprietary acquisition route to collect offline-verification material.→↓Recover the passcode and decrypt supported user data.→↓Whether every listed build is reachable from a powered-off, locked state without prior screen unlock.
Unverified chainTest one Exynos 1280 and one Unisoc T7xx device while recording boot mode, disassembly, and patch level.
interesting · Mobile — physical

GrayKey claims it can preserve an iPhone’s After First Unlock state through inactivity reboot or power loss.

Affects

Apple iPhone devices running iOS, when seized after at least one unlock and connected to Magnet GrayKey Preserve or a GrayKey system with Evidence Preservation Mode.

The claim would extend the forensic-access window indefinitely, but it applies only after the phone has already entered After First Unlock state and the preservation mode is activated.

Detail and 5 sources

We do not know the mechanism, supported hardware and iOS boundary, or whether the behavior works on fully updated devices.

Chain to watch
Obtain an iPhone that has been unlocked since boot.→↓Activate GrayKey preservation while it remains in After First Unlock state.→↓Test whether reboot or power loss ends the forensic-access window.→↓Current-version compatibility and preservation of the relevant keybag state have not been independently verified.
Unverified chainObserve keybag state on fully updated iPhones before and after inactivity reboot and power loss.
interesting · Bluetooth — mobile

Google says a malformed Android Bluetooth storage value can corrupt the heap and reach remote code execution.

Affects

Android's privileged Bluetooth service on Android 16, Android 16 QPR2, and Android 17 devices.

The defect is a heap out-of-bounds write in cfg2prop inside the privileged Bluetooth component, and Google classifies the result as remote code execution without user interaction.

Detail and 2 sources

The missing fact is the attacker’s starting position: the bulletin does not identify the transport, profile, pairing state, or privileges retained after execution.

Chain to watch
Supply a malformed value that reaches cfg2prop.→↓Trigger a heap out-of-bounds write in the privileged Bluetooth component.→↓Reach the remote-code-execution consequence described by Google.→↓The initiating Bluetooth route and post-exploitation boundary are unpublished.
Unverified chainMap the affected caller from the fix and reproduce it while recording transport, pairing state, process identity, and SELinux domain.
interesting · Bluetooth — mobile

Three Android Bluetooth flaws let locally running code cross into the privileged Bluetooth service.

Affects

Android's privileged Bluetooth service on Android 16, Android 16 QPR2, and Android 17 devices.

Google classifies an uninitialized-pointer path, an AVRCP race, and a snoop-filter validation flaw as local elevation of privilege.

Detail and 4 sources
interesting · Documents — RCE

Opening a crafted Calc spreadsheet can make LibreOffice fetch and execute attacker-hosted Java code.

Affects

LibreOffice Calc, the spreadsheet application and headless document converter available across desktop and server platforms.

A saved external-data mapping can select the SQL provider and retrieve a remote JDBC driver during document loading; the driver’s code runs as the LibreOffice process.

Detail and 2 sources

The route crosses the document-to-code boundary for desktops and automated document pipelines, but it requires the file to be opened with LibreOffice Java support available.

interesting · Mobile — privilege

Samsung says a WSM use-after-free may execute code with Android system privilege.

Affects

Samsung Mobile devices running Android 14 through 17 with security software older than the October 2026 maintenance release.

The reported consequence crosses the application privilege boundary, but Samsung does not disclose the invoking IPC route, required permissions, or affected device coverage.

Detail and 1 source

We also do not know whether an ordinary application can reliably control execution after triggering the lifetime error.

Chain to watch
Invoke the vulnerable WSM service path from local code.→↓Trigger the use-after-free.→↓Attempt controlled execution with Android system privilege.→↓The reachable IPC entry point, permission checks, and reliability from an ordinary application are unknown.
Unverified chainDiff the WSM service around Samsung’s October release and reproduce the changed path under allocator instrumentation.
interesting · Firmware — edge

HPE disclosed a pre-authentication remote validation failure in iLO 7.

Affects

HPE Integrated Lights-Out 7, the embedded management controller in HPE ProLiant Gen12 servers.

The affected range is iLO 7 firmware before 1.25.00, and exploitation requires network access but no authenticated management session.

Detail and 5 sources

The disclosure does not establish whether success yields an iLO session, Compute Ops Management impersonation, direct server controls, or some narrower effect.

Chain to watch
Reach an iLO 7 interface running firmware before 1.25.00.→↓Trigger the remote user-validation failure.→↓Determine the resulting management identity and operations.→↓The vulnerable protocol, prerequisite, granted role, and post-validation authority are missing from the retrievable material.
Unverified chainRetrieve HPESBHF05163 rev.1 or HPE’s machine-readable advisory and map the resulting authority.
interesting · Research — privilege

A workspace writer can redirect an approved Claude Code edit outside the project through a symlink race.

Affects

Claude Code, Anthropic's local coding-agent command-line application.

The checked path can be atomically replaced before write-time resolution, causing Claude Code to modify an attacker-selected file with the session user’s authority.

Detail and 1 source

The boundary failure is real but requires an adversarial concurrent workspace writer to win the race.

interesting · Edge

Unauthenticated callers can read known files from the web roots of eight Atlassian server products.

Affects

Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo and Crowd Data Center, plus Crucible and Fisheye; self-managed enterprise collaboration and development servers.

The traversal reaches specifically named files beneath the application web root without authentication across the affected self-managed products.

Detail and 3 sources
interesting · Research — edge

MCP Python servers can accept a bearer token minted for another service behind the same authorization server.

Affects

The Model Context Protocol Python SDK, used to build HTTP-accessible MCP servers.

A caller with a valid sibling-service token can authenticate to an affected MCP HTTP server when the verifier does not enforce the receiving resource as the token audience.

Detail and 1 source

The repair is incomplete by default: upgrading adds resource validation but leaves it disabled until the operator configures it.

interesting · Cloud privilege

A SageMaker project contributor can execute commands in another member’s Studio Space and take that member’s temporary role credentials.

Affects

Amazon SageMaker Distribution images used by SageMaker Unified Studio Spaces in AWS.

Crafted project connection data reaches an unneutralized shell invocation when another member’s Space validates connections during startup.

Detail and 2 sources

The injected command runs in the peer’s Space; when Trusted Identity Propagation is enabled, it can obtain that member’s temporary execution-role credentials for downstream AWS calls.

interesting · Mobile — research

A rooted analysis device can strip Promon Shield from some protected Android apps while leaving them runnable.

Affects

Promon Shield for Mobile, a commercial runtime self-protection layer embedded in Android banking, payment and game applications.

The demonstrated method extracts protected material after runtime decryption and replaces Shield’s native implementation with compatible JNI behavior that neutralizes active checks.

Detail and 2 sources

It requires a copied APK, a rooted device, and skilled app-specific work; it does not cover Promon attestation. Promon reproduced the method and released hardened versions.

interesting · Edge — RCE

Public code connects HFS administrator-session forgery to server-side code execution.

Affects

Rejetto HFS 3.x, a cross-platform self-hosted HTTP file-sharing server.

Unauthenticated login responses expose consecutive output from the generator used to derive HFS’s cookie-signing key. Recovering that state permits a forged administrator session, after which set_config and server_code execute JavaScript in the server context.

Detail and 6 sources
interesting · Edge — RCE

Pre-2026.4.2 P4 Search containers expose an unauthenticated debugger or highest application privilege.

Affects

Perforce P4 Search, a Windows/Linux search service connected to Helix Core/P4 Server and commonly deployed in containers.

A network peer can use unauthenticated JDWP for code execution as the service account, or obtain top application privilege through a documented default token or a fail-open blank token.

Detail and 5 sources
interesting · Privilege — edge

Public code shows that Loom for AWS can make every network client a super-admin when no identity provider is active.

Affects

Loom for AWS, AWS Labs' self-hosted AI-agent orchestration and management platform.

Before version 1.6.1, the authentication dependency returns a fixed super-admin identity without examining an Authorization header when neither Cognito nor an active external provider is configured.

Detail and 4 sources
interesting · Edge — RCE

A reachable LightLLM visual-only node executes unauthenticated pickle payloads as its service account.

Affects

LightLLM, a Linux-based distributed large-model inference server; this path is present on dedicated visual-only multimodal nodes.

The optional visual-only RPyC service binds without an authenticator and enables pickle deserialization; a crafted remote_infer_images argument executes before type handling.

Detail and 4 sources
interesting · Wi-Fi — RCE

A Maestro bearer URL can authorize commands as the logged-in user.

Affects

Maestro, a desktop application for controlling development tools and AI agents on Windows, macOS, and Linux

The UUID can be recovered from plaintext LAN traffic, a leaked pairing or sharing URL, a broadly readable local file, or a cross-origin connection to services bound on all interfaces.

Detail and 3 sources

Possession of that URL reaches Maestro’s interactive terminal with the user’s authority. The coordinated advisory says mitigations shipped for the exposed bind, bearer credential, cross-origin paths, and file permissions.

interesting · Wi-Fi — firmware

A valid TL-WR841N administrator can turn an IPv6 Gateway value into operating-system command execution.

Affects

TP-Link TL-WR841N v14, an embedded home Wi-Fi router

The path crosses from authenticated web administration into the router’s operating-system command context by incorporating the supplied gateway value into a system command.

Detail and 1 source

It requires LAN access and valid administrator credentials, affects the v14 hardware revision, and has region-specific fixed firmware.

interesting · Mobile — physical

Physical possession now lets Passware recover passcodes on five Exynos 1280 Galaxy phones and decrypt supported MDFPP/SDP data.

Affects

Passware Kit Mobile, a commercial mobile-forensics product for extracting and decrypting locked Android devices.

Passware says Kit Mobile 2026 v5 supports five Exynos 1280 Samsung models; the Galaxy A53 is the only one named publicly in the supplied evidence. With physical custody, the workflow uses model-specific low-level acquisition, offline GPU guessing, and the recovered passcode to decrypt supported data.

Detail and 2 sources

We do not know the entry primitive, the other four models, the required boot state, or the exact model and version boundary for MDFPP and SDP. The proprietary method has not been independently reproduced in public.

Chain to watch
Obtain physical possession of a supported locked Samsung phone.→↓Connect it through Passware’s model-specific low-level acquisition path.→↓Extract the material required for offline passcode verification.→↓Test passcode candidates with GPU acceleration; Passware reports more than 14,500 attempts per second for Exynos 1280 devices.→↓Use the recovered passcode and Passware’s MDFPP/SDP support to decrypt supported device data.→↓Passware has not publicly identified the precise Exynos entry primitive, the other four supported models, or the complete MDFPP/SDP and patch-level boundary.
Unverified chainObtain Passware’s acquisition guides and device matrix, or independently test each named model while recording board access, boot state, encryption configuration, and patch level.
interesting · Boot chain

A systemd 262 and dracut integration gap can preserve the PCR state meant to block TPM-bound LUKS key release after an attacker-controlled root boots.

Affects

Linux systems using systemd 262, a Dracut-generated initramfs, TPM2-backed LUKS auto-unlock, and a policy that relies on PCR15 changing from zero before leaving the initramfs.

systemd 262 moved volume-key measurement to systemd-pcrextend.socket. Affected dracut initrds omit that socket; cryptsetup warns but continues, so PCR 15 can remain zero through leave-initrd.

Detail and 6 sources

With device custody, an attacker can retain the signed UKI while substituting the root filesystem. A proposed dracut change restores the socket, but affected pre-fix images remain accepted and revocation status is unresolved.

Chain to watch
Attacker obtains the powered-off device and substitutes an attacker-controlled root filesystem while retaining the target's signed UKI→↓Secure Boot and the configured PCR 7 policy still admit the signed boot chain→↓systemd-cryptsetup attempts to measure the unlocked volume key through systemd-pcrextend.socket→↓The dracut-generated initrd lacks that socket, so measurement fails with a warning while boot continues→↓PCR 15 remains at the enrolled zero value through the transition to the attacker-controlled root→↓The TPM policy can still authorize release of the sealed LUKS key after the trust boundary has been crossed→↓The missing PCR extension is demonstrated, but public evidence does not show the TPM releasing and the attacker using the original disk’s LUKS key from the substituted root.
Unverified chainReproduce systemd 262 with dracut 111 or 112, boot its signed UKI against a controlled alternate root, and test whether the TPM releases a usable key for the original LUKS volume after leave-initrd.
Also noted0

No additional findings today.

What was checked · 2 quiet
Zero-clickQuiet

No new zero-click primitive survived; the authoritative August Android tables remain unavailable.

FirmwareQuiet

iLO 7 validation and narrow router command paths remain constrained by missing exposure or authority details.

Get it by email

The same brief, every morning. One email a day, nothing else.

fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, October 6, 2026