Apple published updates, but end-of-life iPhones remain reachable; mitigations across the agent-harness class are incomplete and have not removed the capability.
JavaScriptCore renderer corruption → GPU process → Apple driver race → kernel read/write.
Apple iPhone XS through iPhone 16 running vulnerable iOS 18 releases when Mobile Safari loads a site using one of 13 trojanized OphimCMS or KKPhim Packagist themes.
Drive-by spyware execution with kernel memory access and bulk credential, message, photo, and cryptocurrency-wallet-secret exfiltration
The exploit chain reaches kernel read/write through renderer corruption and the GPU process; the spyware collects secrets from the handset.
The campaign began with an attacker-controlled Packagist theme served by a streaming site. The victim needed only to load the affected page in Mobile Safari.
JavaScriptCore supplied renderer read/write; Mach and IOSurface primitives then reached the GPU process and an Apple driver race supplied kernel read/write.
Collection included keychains, Wi-Fi credentials, messages, photos, cookies and account data. An August redeployment added wallet seed phrases.
Apple published updates, but the assessed boundary remains open on end-of-life hardware and the capability is not fully removed.
The definite conclusions are limited to the documented exploit chain; build-specific signing state and undocumented recovery or alternate interfaces remain unverified.
Across 12 tested harnesses, data crossed role or scope boundaries and reappeared as higher-authority context.
Twelve coding and general-purpose agent harnesses that assemble instructions from web pages, repositories, archives, skills, subagents, and tool output
Host command execution through automatic promotion of attacker-controlled content into privileged agent context
The changed assumption is the data-versus-instruction boundary itself: every evaluated harness admitted a demonstrated form of context privilege escalation.
The attacker controls a website, repository, archive, skill or tool response that the victim asks an affected agent to process. Some chains also reuse a routine command approval already granted in the session.
In the Claude Code demonstration, exploring an archive discovered a nested SKILL.md; its inline action reused an approved Node command and executed with the agent user's privileges.
Some vendors shipped mitigations, but not all did, and the assessed capability remains present.
Virtualizor, a Linux virtualization-management control plane installed on servers that host and administer virtual machines
The unauthorized route diverted ACME and update traffic to a validly certified attacker endpoint. With no package-signature check, the updater installed a modified package and persistent systemd service.
Package signing is promised, but the vendor did not say that enforcement has shipped.
CryptoPro Secure Disk for BitLocker, preboot authentication and disk-encryption software deployed on Windows systems, embedded devices, and some ATM platforms.
The attacker must be able to image or relocate the disk. Serialized TPM secrets in unused sectors then combine with an insufficient PCR policy to permit unsealing outside the intended state.
The researcher reported validating the vendor's fixes.
CryptoPro Secure Disk, preboot authentication and disk-encryption software used on Windows and embedded systems, including some ATM security deployments.
CryptoPro selects the first partition with a hardcoded type instead of certifying that it is the intended partition.
We do not know whether the minimum starting position is offline physical access, an already privileged host process or either one.
A patch is available and is assessed to remove this partition-selection capability.
Cisco Secure Email gateways running AsyncOS and configured to use S/MIME for gateway-to-gateway email protection
Insufficient ciphertext-integrity validation lets an attacker modify intercepted gateway traffic into a plaintext-recovery path.
Cisco says fixed software is available.
PaperCut NG and PaperCut MF print-management application servers on Windows and Linux
A direct-component request makes the authorization check trust a public page while invoking an administrative action. That access changes database lookup configuration so PaperCut loads an attacker-selected Java class.
Huntress reproduced SYSTEM execution on stock Windows and observed the same exploitation sequence in customer environments.
HPE Aruba Networking AOS-CX, the operating system on enterprise Ethernet switches
The advisory identifies daemon buffer overflows, an API arbitrary-file-write path and a CLI format-string flaw. Exposure depends on the service, and some paths are adjacent-network only.
HPE published fixed software.
Kestra OSS workflow-orchestration servers, commonly deployed as containers on application and automation infrastructure
Any route ending in /configs escapes the authentication filter, allowing an unauthenticated caller to create and execute a script workflow as uid 0 in the worker container.
The service is commonly exposed on TCP port 8080 or a mapped container port.
Microsoft observed workflow-origin shell execution, and CISA added the vulnerability to KEV on September 2. Kestra has published a fix.
SonicWall SMA1000 6210, 7210, and 8200v secure remote-access and SSL-VPN appliances
SonicWall confirms active exploitation of both vulnerabilities.
The reported composition joins pre-authentication SSRF or unintended forwarding to authenticated command injection, but the public record does not demonstrate the authentication transition.
Fixed firmware is available for both supported branches.
SPIP, an open-source content-management system running public websites on PHP web servers
SPIP 4.4.22 fixes both paths, and the project's separate security-screen mechanism does not cover them.
WAGO 750-831 programmable logic controllers used in industrial automation, running the embedded Nucleus TCP/IP stack.
The target-specific sequence uses an oversized pre-authentication USER payload and a CWD request without a CRLF so normal FTP processing does not erase the shellcode.
Two payloads emitted attacker-selected ICMP and UDP traffic from the physical controller, and the original advisory lists the 750-831 family as affected.
ShizenBox2, a network-connected energy-IoT edge controller used to monitor and control household energy equipment.
The password-change API trusted the username supplied in the request instead of the authenticated session identity.
Edge-app 3.1.16 binds the operation to the session identity.
Shizen Connect ShizenBox2, an edge appliance administered through the vendor's dev-conf software and booted through U-Boot.
The shipped console had no password and allowed unrestricted rootfs reads and writes after boot interruption through the serial port.
Authenticated U-Boot began shipping through FOTA with dev-conf 1.1.0.
TOTOLINK A720R wireless routers running the affected embedded firmware.
The exploit starts with LAN access and a valid router-administrator session.
The disclosure demonstrates redirected calls and Telnet activation, but not an interactive shell or attacker-chosen command.
CryptoPro partition selection and ShizenBox2's unauthenticated U-Boot console exposed product-specific boot paths; no universal Secure Boot bypass emerged.
No new Bluetooth capability was established; current Unitree and BlueZ activity restated previously published paths.
Locked-phone gallery access changed under physical possession; no new receipt-only message or media-parser execution path was established.
fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place. A CVE is an input, not an event. When nothing qualifies, the brief says so. Every morning.