Containment, an unanswered ring and passive mail preview can each now end in attacker code execution or SYSTEM.
Existing AppContainer execution is enough to reach the vulnerable path.
Supported Microsoft Windows client and server systems using the built-in ALPC inter-process communication mechanism.
Local sandbox escape and SYSTEM privilege escalation
The broken boundary is containment itself: code that was already restricted can cross the user or AppContainer boundary and become SYSTEM, and exploitation is active.
An attacker begins with low-privilege or AppContainer code execution, triggers the heap overflow with crafted ALPC activity and crosses into SYSTEM.
A fix is published and reaches end-of-life hardware. We do not know whether pre-fix images remain accepted or whether revocation is complete.
No public patch diff or reverse-engineering analysis was available in the reviewed material.
The phone only has to ring; an existing contact is the gate.
WeChat, Tencent’s messaging and calling application on Android and iOS.
Zero-click WeChat account takeover and contact-to-contact worm propagation
A caller already trusted as a contact can turn one compromised account into the next calling point without action from the recipient.
While the phone rings, WeChat processes attacker-controlled VoIP data. Memory corruption yields application-context code execution, including the ability to read and send messages and place calls as the victim.
Researchers demonstrated the chain from a Pixel to an iPhone and onward to another Pixel without either call being answered. Tencent confirmed the finding and deployed client and server mitigations.
Mitigation coverage reaches end-of-life hardware, but pre-fix image acceptance and revocation completeness remain unresolved.
The evidence establishes global mitigation of the demonstrated exploit, but not removal of the underlying client vulnerability.
Microsoft Windows 11 and Windows Server 2025, desktop and server operating systems.
Low-privilege code on an affected Windows 11 or Windows Server 2025 host can arrange a link condition that redirects the updater’s privileged file access and yields SYSTEM.
Microsoft’s CNA record establishes the affected and fixed builds, and exploitation is reported in the wild. We do not know the state of pre-fix image acceptance, revocation or end-of-life hardware coverage.
Android phones and other Android devices using the platform wpa_supplicant Wi-Fi Direct implementation.
A crafted Wi-Fi Direct provisioning-discovery bootstrap request reaches p2p_process_prov_disc_bootstrap_req(), causes a heap out-of-bounds write and can execute code in the Wi-Fi component.
Google published per-branch fixes and affected ranges. We do not know whether old images remain accepted, revocation is complete or end-of-life devices are covered.
Android's system Bluetooth stack on phones, tablets and other Android devices
Crafted SDP data reaches heap-buffer overflows in Android’s request-processing and attribute-building paths, which Google classifies as no-interaction remote code execution.
Bluetooth radio reachability is required, but we do not know whether the attacker must first pair or establish a connection. Android OSV provides per-version fixes.
This remains Secondary because the published fix was not read for this brief.
Android's system Bluetooth service on phones, tablets and other Android devices
A logic error in AdapterService.handleBondStateChanged lets a bond-state transition bypass pairing consent and produce remote privilege escalation without interaction.
Radio reachability is required, but the initiating state and precise transport are not public. The September 5 patch level addresses the affected Android families.
SAP NetWeaver Message Server on ABAP systems using affected 9.x kernels, including S/4HANA and S/4HANA Cloud Private Edition deployments.
A crafted registration packet sent to public port 36NN makes the Message Server trust an attacker-controlled address as an internal application-server component.
That trust propagates across the cluster, allowing the attacker to reach SAP Gateways, invoke RFC-callable external programs and execute commands as the SAP operating-system administrator.
SAP kernel-based business systems, including SAP S/4HANA, ERP/ECC, NetWeaver AS ABAP, Web Dispatcher, BW/4HANA, Enterprise Portal, PI/PO and Solution Manager.
Affected HTTP(S), SAP GUI and RFC listeners pass a client-supplied Extended Passport into shared kernel code before authentication and authorization checks.
A crafted passport can take control of the receiving process and run operating-system commands as the SAP installation owner.
Cisco UCS servers and UCS-based compute, security, management, analytics, and network-edge appliances running vulnerable BIOS or firmware releases with UEFI Secure Boot enabled.
A user with KVM credentials, or anyone at the physical console, can enter the embedded shell and use its memory-write commands to overwrite Secure Boot-related values.
That permits unauthorized pre-OS execution despite Secure Boot.
This remains Secondary because the partial fix was not read for this brief.
Supported Windows desktop and server releases implementing RNDIS, Microsoft's network-device protocol commonly associated with USB peripherals and tethering.
Malformed input reaching an active RNDIS interface can trigger a heap overflow and execute code on the Windows host.
We do not know whether the cheapest attacker position is a routed peer, a LAN peer or a malicious attached or tethered device.
Tozed ZLT X300 and X300A 5G CPE routers, cellular gateways running an aarch64 OpenWrt-derived firmware.
After a router attaches to the rogue cellular network, the attacker can impersonate the carrier’s TR-069 server and supply IPPingDiagnostics.Host.
netcwmpd inserts that value into a command passed to system_by_root() without validation, producing uid 0 shell execution. The researcher reproduced the chain on owned hardware and a private LTE network.
No patch is available.
Android kernels containing the vulnerable Linux TIPC fragment-reassembly implementation.
Attacker-controlled fragments delivered to an enabled TIPC transport can leave a stale skb pointer that is freed twice after validation fails.
Google classifies the result as no-interaction kernel code execution, but no cited source establishes a reachable TIPC bearer on a factory-stock handset.
This remains Secondary because the published fix was not read for this brief.
Microsoft Outlook and related Office installations on Windows and macOS, including Microsoft 365 Apps and perpetual Office releases.
Outlook automatically processes the message in its Reading Pane, where a heap-based buffer overflow can produce code execution with the logged-on user’s privileges.
Microsoft published affected and fixed build ranges. Fix coverage reaches end-of-life hardware, but pre-fix image acceptance and revocation completeness remain unresolved.
SAP cluster trust injection, shared-kernel pre-authentication execution and ScreenConnect participant-role bypass changed reachable edge paths.
The strongest research-backed changes were the WeChat call chain, the ALPC sandbox escape and passive Outlook execution.
The same brief, every morning. One email a day, nothing else.
fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.