important2 findings, 15 signals5 min read

A clicked Chrome link has delivered code beyond the renderer sandbox, and an unanswered WeChat call can take over an account and propagate.

BlueMoon and WeChat show complete delivery-to-execution paths demonstrated in the field or on physical devices.

Priority findings2
01
High
Browser to host
Confirmed
CVE-2026-85046

BlueMoon turns one clicked Chrome link into attacker-chosen execution outside the renderer sandbox.

Proofpoint recovered deployed samples associated with four espionage clusters.

Affects

Google Chrome on Microsoft Windows desktops and servers targeted by the BlueMoon espionage exploit kit.

What it enables

Web-delivered command execution outside the Chrome renderer sandbox

Deliver a link to a BlueMoon-controlled page and induce the recipient to open it in affected Chrome.Exploit CVE-2026-85046 to obtain address disclosure, fake-object construction and arbitrary read/write inside the V8 heap cage.Exploit CVE-2026-87491 to replace WebAssembly compiled-function bodies with attacker shellcode and escape the V8 sandbox.Exploit CVE-2026-85880 through Windows ALPC/WNF to obtain kernel read/write and enable SeDebugPrivilege in the renderer token.Inject a CreateProcess stub into Chrome’s broker process, download an operator-selected executable and run it outside the renderer sandbox.
Why this matters

What changed is composition and use: three primitives now form an observed click-to-broker execution chain.

Detail and 2 sources
Required access

Internet delivery of a malicious link followed by the recipient opening it in affected Chrome on Windows

Affected versions

Chrome before 152.0.7977.82/.83 for CVE-2026-85046, Chrome before 153.0.8010.36/.37 for CVE-2026-87491, Windows builds 17763, 19041–19045, 20348 and 22000 in the observed BlueMoon chain

After the recipient opens a link in affected Chrome on Windows, the chain uses V8 read/write, replaces WebAssembly code and then uses an ALPC/WNF kernel exploit.

The final stage enables SeDebugPrivilege, injects into Chrome’s broker and runs an operator-selected executable outside the renderer sandbox.

Google confirms that Chrome 153 fixes CVE-2026-87491. The operational evidence makes stale affected Windows browser builds an immediate update target.

Evidence
Proofpoint recovered and analyzed deployed exploit-kit samples from four actor clusters and documented each chain primitive and final payload execution path.Google’s stable-channel notice confirms the CVE-2026-87491 fix and Chrome 153 versions.
Share this finding
02
High
Zero-click messaging
Confirmed

A WeChat call from an existing contact can execute code, take over the account and propagate without being answered.

Attacker-controlled VoIP data reaches the vulnerable path while the phone is still ringing.

Affects

WeChat, Tencent's mobile messaging and calling application on iOS and Android.

What it enables

Zero-click cross-platform code execution, account takeover, and wormable propagation

Attacker controls a WeChat account already on the target's friend list.Attacker initiates a crafted WeChat voice call.The recipient's client processes attacker-controlled VoIP data before the call is answered.The flaw yields code execution and control of the recipient's WeChat account.The compromised account calls its own contacts, repeating the chain without their interaction.
Why this matters

The chain turns an existing contact relationship into a no-interaction propagation path across iOS and Android.

Detail and 2 sources
Required access

Internet access and a WeChat account already present on the target's friend list; the recipient need not answer or interact with the call.

Affected versions

WeChat 8.0.76 for Android (demonstrated vulnerable), WeChat 8.0.75 for iOS (demonstrated vulnerable); the complete affected range is not public

Proof of concept

Demonstrated by the researcher

A compromised friend account places the crafted call; pre-answer processing triggers memory corruption, code execution and account control.

Researchers demonstrated the full chain across three physical devices, including onward calls from a newly compromised account.

Updated clients and Tencent’s server-side block are the documented mitigations. We do not know whether every underlying root cause was removed.

Evidence
Calif demonstrated the full chain across three physical iOS and Android devicesIndependent reporting corroborated the tested and mitigating client versions and Tencent's server-side blockTencent has not publicly documented the underlying defect or confirmed that every root cause was removed
Share this finding
Signals15
important · Edge — SonicWall

SMA1000 compromise is being converted into Active Directory credential theft and DCSync.

Affects

SonicWall SMA1000, an enterprise VPN and secure-access appliance deployed physically or virtually at the network edge.

The public proxy reaches localhost Erlang; its hard-coded cookie yields appliance commands, stored LDAP credentials and access to internal directory services.

Detail and 4 sources

Campaign artifacts show SAM and LSA extraction and DCSync, while working public code covers the initial unauthenticated entry chain.

After appliance compromise, containment has to include the directory credentials and systems reached from the appliance.

important · Windows DNS

A single unauthenticated DNS packet can execute code on affected Windows DNS servers.

Affects

Windows DNS Server on supported Windows Server releases and the DNS implementation in Windows 10 1607 and 1809.

The packet triggers a use-after-free in DNS processing and reaches the service context without authentication.

Detail and 3 sources
important · Edge — Check Point

Unauthenticated VPN negotiation can execute code on affected Check Point gateways and management servers.

Affects

Check Point Security Gateway, Spark appliances and, for CVE-2026-85103, Security Management Server installations processing VPN certificates.

Malformed certificate data can reach either improper validation or an ASN.1-decoding heap overflow in deployments using Remote Access or Site-to-Site VPN.

Detail and 4 sources
important · Boot chain — GIGABYTE

Root on affected GIGABYTE systems can reopen an embedded UEFI shell and bypass Secure Boot.

Affects

Certain GIGABYTE motherboards whose BIOS includes the affected AMI Aptio UEFI BDS module.

Redundant boot entries survive vulnerable cleanup, letting the shell alter Secure Boot policy in memory and load unverified pre-OS code.

Detail and 2 sources

The prerequisite remains administrative or root control; today’s addition is the GIGABYTE-specific root cause and scope, not a new initial foothold.

important · Linux privilege

A local Linux user can race gvfsd-admin into handing over a root-owned file and escalate to root.

Affects

GVfs, the GNOME virtual-filesystem service and its privileged admin backend on Linux desktops.

The race swaps a private socket pathname for a symlink before a privileged chown, allowing ownership of a security-sensitive root file to pass to the user.

Detail and 3 sources
important · Cloud privilege — AWS

Restricted SSM port forwarding can be turned into the managed instance’s IAM role.

Affects

AWS Systems Manager Agent, endpoint-management software on EC2 instances, on-premises servers and other managed machines.

A permitted principal uses an equivalent link-local address representation to bypass the destination check, reach instance metadata and retrieve temporary role credentials.

Detail and 3 sources
important · Mobile Wi-Fi

Nearby Wi-Fi traffic can make Android read beyond its 802.11 parser buffer and disclose information.

Affects

Android phones, tablets, and other devices using Android's wpa_supplicant-derived Wi-Fi stack.

Malformed EHT-operation data reaches an incorrect bounds check without user interaction; Google has published a fix.

Detail and 2 sources

We do not know which frame role reaches the parser or how the transmitter observes the out-of-bounds bytes.

Chain to watch
Recover the AOSP fix and identify the caller that reaches the EHT parser.Trace any response path that could expose out-of-bounds bytes to the transmitter.The observable extraction path from the parser’s out-of-bounds read remains unestablished.
Unverified chainReproduce malformed EHT Operation elements while tracing parser callers and outbound responses.
important · Nintendo Switch Wi-Fi

A nearby attacker can execute arbitrary code on an unpatched Nintendo Switch through local wireless networking.

Affects

Nintendo Switch, Switch Lite, and OLED-model game consoles running Nintendo's embedded system software.

The vulnerable function must be active and its temporary network information exposed; crafted traffic then turns a stack overflow into a ROP chain.

Detail and 2 sources

The resulting execution privilege and directly recoverable console data remain undisclosed.

Chain to watch
Map the vulnerable local-wireless service’s process and privilege context.Determine what console data and persistence become reachable after ROP execution.Nintendo has not disclosed the execution privilege or directly accessible data.
Unverified chainAnalyze the pre-23.0.0 local-wireless service and map the ROP execution context.
important · AI infrastructure — LiteLLM

LiteLLM’s default management key can turn an exposed pre-1.82.0 proxy into effective unauthenticated root execution.

Affects

Self-hosted LiteLLM AI gateways, commonly deployed as containers in cloud environments to proxy model-provider traffic.

The documented sk-1234 key, or no master key, exposes administrative custom-code guardrails that run uploaded Python in the root proxy process and can expose cloud credentials.

Detail and 3 sources
important · Mobile — OnePlus

An ordinary Android app can extract an active OnePlus Cloud session token from the preinstalled account provider.

Affects

The preinstalled OnePlus Account application on OnePlus 13R Android phones, which brokers authentication to OnePlus Cloud services.

The provider’s custom permission lacks signature-level protection, and September retesting confirmed that the returned token was accepted by the regional API.

Detail and 2 sources

The flaw remains unresolved, but end-to-end profile modification was not reproduced on current US or EMEA test accounts.

Chain to watch
Retest token-authorized API calls with a supported regional account.Map the read and write operations authorized by the extracted token on current firmware.The token’s full authorized API scope on current firmware remains unknown.
Unverified chainRepeat signed and encrypted OnePlus Cloud API requests with a supported regional account.
important · Physical — Windows

AOMEI Backupper lets an unprivileged Windows user rewrite the system disk and install pre-OS UEFI code.

Affects

AOMEI Backupper, Windows backup and disk-cloning software that installs the amwrtdrv.sys kernel driver.

Its world-accessible driver performs unrestricted physical-disk operations without checking the caller’s token.

Detail and 3 sources

Published code demonstrates a GPT and UEFI-payload chain to pre-OS execution when Secure Boot is disabled; no corrected AOMEI release was established.

important · Bluetooth — Zephyr

An unauthenticated Bluetooth Classic peer can inject data into Zephyr L2CAP handlers before authentication completes.

Affects

Zephyr, an embedded real-time operating system used in connected devices

While a dynamic channel is still half-open, Zephyr can resolve its destination CID and dispatch attacker-controlled data without requiring the CONNECTED state.

Detail and 3 sources
important · Edge — TP-Link

One adjacent-network packet can execute commands as root on a Deco BE11000.

Affects

TP-Link Deco BE11000 v2, an embedded tri-band Wi-Fi 7 whole-home mesh router.

A crafted UDP packet reaches the TDDP module and triggers operating-system command injection with root privileges.

Detail and 2 sources
important · Bluetooth audio

A nearby stranger can silently bond with Skullcandy Dime 3 earbuds and capture live microphone audio.

Affects

Skullcandy Dime 3 model S2DCW, consumer Bluetooth wireless earbuds.

NoInputNoOutput pairing succeeds outside pairing mode without owner approval, after which the attacker reconnects as trusted and reaches the headset microphone.

Detail and 2 sources
important · Document trust

One signed PDF can present different visible content in Apple PDFKit and independent renderers.

Affects

Apple PDFKit, the PDF renderer used by Preview and applications on iPhone, iPad, and Mac.

Researchers placed an ordinary JPEG beneath a JPEG 2000 image in a JPX container. Apple PDFKit exposed the lower image, while independent renderers displayed the JPX layer.

Detail and 2 sources

That gives a sender one authenticated artifact whose visible meaning depends on the reviewer’s software.

While this divergence remains, high-consequence PDF reviews should compare a trusted rasterization or use the same controlled renderer on every side.

Also noted0

No additional findings today.

What was checked · 3 quiet
Boot chain & TPMQuiet

AOMEI adds an ordinary-user-to-UEFI chain when Secure Boot is disabled; GIGABYTE’s update clarifies an already privileged embedded-shell path.

Physical accessQuiet

AOMEI converts an ordinary Windows foothold into raw-disk and demonstrated pre-OS control; exact recent BitLocker triggers remain unresolved.

ResearchQuiet

Operational BlueMoon use and SMA1000-hosted DCSync changed exploitation evidence; Check Point’s VPN execution scope also widened.

Get it by email

The same brief, every morning. One email a day, nothing else.

fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 11, 2026