The first starts when a developer opens an untrusted workspace; the other two start with remotely delivered image data or a nearby Wi-Fi peer.
Nested settings filtering and workspace-scoped remote-agent configuration opened separate routes through Restricted Mode.
Visual Studio Code, a cross-platform desktop code editor with Workspace Trust isolation for untrusted repositories.
Code execution as the user despite Restricted Mode
Restricted Mode is the boundary developers rely on when opening unfamiliar repositories without granting them trust.
The user only has to open the attacker-controlled workspace: crafted nested settings can evade restriction checks, or remote-agent settings can select an attacker service with local-file permissions.
The public fixes add nested-setting regression coverage and remove remote-agent-host selection from workspace-controlled scope.
We do not know whether updating also neutralizes every malicious configuration that an older build already accepted.
Both paths begin with heap overflows in Samsung's libimagecodec.quram.so decoders.
Samsung Mobile Devices using Samsung's proprietary image-decoding library on Android 14 through Android 17.
Remote code execution during DNG or JPEG image decoding without user interaction
The Samsung records require neither privileges nor user interaction, moving these decoder bugs from memory corruption to a passive remote code-execution capability.
An attacker sends crafted image data through a path that causes the device to invoke the DNG or JPEG decoder; the resulting heap overflow permits code execution during processing.
Samsung says the flaws were addressed in a shipped maintenance release.
We still do not know the concrete delivery transport or the additional attack requirement recorded by Samsung, and no public trigger artifact was identified.
No public patch diff or vendor test corpus was available for determining how the fixed decoders handle the original triggering images.
An oversized PBMA cookie length drives a heap write beyond the allocation in P2P2 bootstrap processing.
Android smartphones and other Android devices using the platform wpa_supplicant Wi-Fi Direct implementation.
Adjacent remote code execution in the Android Wi-Fi service
This crosses directly from an unauthenticated radio peer into Android's Wi-Fi service without asking the user to approve a connection or take another action.
The attacker enters Wi-Fi range, answers the target's P2P2 bootstrap Provision Discovery Request with an oversized cookie length, and causes wpa_supplicant to copy beyond its heap buffer.
The AOSP change and Android bulletin connect that attacker-controlled write to proximal remote code execution requiring no privileges or interaction.
The published fix closes this oversized-cookie path.
The revocation answer means the patch has no revocation dependency; it does not describe a separate revocation campaign.
Agent Payments Protocol (AP2), a protocol and reference implementation for agent-mediated shopping and payments.
A merchant can place instructions or false claims in product text that the agent consumes before it creates the signed checkout artifacts.
The reported tests produced cross-user credential retrieval, mismatched carts and more expensive purchases across 17 Google models, three frameworks and Google's consumer assistant.
The public benchmark includes reproduction material, and no fix is identified.
This stays secondary because current production adoption and reach are not established.
MikroTik RouterOS, the operating system used by MikroTik routers and wireless network appliances.
Malformed RSA/PKCS#1 v1.5 signatures and RouterOS's trusted exponent-three root let an attacker construct a forged intermediate and issue a certificate for the requested hostname.
CERT Polska confirmed the behavior on real systems with repetition and negative controls.
The attacker still needs destination control or an on-path redirection position.
Fixed releases close the path, but pre-fix images remain accepted and some affected hardware is already end of life.
OpenAI Codex, an AI coding agent running on developer workstations.
The folder supplies Git-command arguments containing control sequences that Codex does not sufficiently neutralize before parsing.
The coordinated advisory identifies current-user code execution and says the flaw is patched.
Microsoft Windows 10, Windows 11, and Windows Server, desktop and server operating systems.
Physical access is sufficient to present input that reaches a heap-based buffer overflow in the storage driver; no account or user interaction is recorded.
We do not know the storage transport, malformed structure, or whether the path works at the lock screen or before sign-in.
The affected population includes end-of-life Windows hardware.
Google Chrome and Chromium-based browsers on selected Windows 10, Windows 11 and Windows Server builds targeted by the BlueMoon exploit kit.
Two V8 flaws provide renderer execution, an ALPC/WNF exploit changes token rights, and injected broker code downloads and executes the operator-selected payload.
Proofpoint observed four threat clusters deploy the complete chain, and Google confirmed exploitation of the V8 components in the wild.
Today's change is evidence that the previously tracked browser bugs were operationally composed through the Windows sandbox boundary; Google and Microsoft have shipped fixes.
Microsoft Windows 10, Windows 11, and Windows Server, desktop and server operating systems with USB and SCSI storage support.
The recorded primitives are two out-of-bounds reads and an untrusted-pointer dereference in kernel-mode storage and hub drivers.
Microsoft does not disclose the triggering descriptors or commands, or the precise privileges obtained.
Affected systems include end-of-life hardware.
Chrome for Android, Google’s mobile web browser running on Android devices.
The victim must load attacker-controlled HTML, which triggers the V8 out-of-bounds write and reaches code execution inside the renderer sandbox.
Chrome for Android 153.0.8010.36 contains the corresponding fix.
The major Android containment boundary still holds in the established chain; we do not know whether observed exploitation included an Android-applicable escape.
GitLab Community Edition and Enterprise Edition, self-managed source-code and CI/CD servers.
A crafted commit request reaches File.read without authentication, and malformed percent encoding reflects the selected file through error handling.
The path has a runnable public reproducer and can disclose every file readable by the GitLab service process.
GitLab has published fixed versions for affected branches.
Microsoft Windows 10, Windows 11, and Windows Server systems using Windows Boot Manager.
Microsoft records physical access, no prior privileges and no user interaction, but supplies no CWE or technical path.
We do not know the resulting privilege, required boot configuration, or relationship to Secure Boot and BitLocker.
Fixed builds exist, but the changed validation or authorization logic has not been established.
MediaTek video-decoder components in Android and embedded devices using the listed MediaTek chipsets.
An unprivileged local process must reach an unpublished video-ingestion route before either missing bounds check produces its heap out-of-bounds write.
We do not know whether the writes are controllable into code execution or which final privilege context they cross.
MediaTek announced a patch and identified the chipset scope.
SonicWall Secure Mobile Access 1000 Series, internet-facing enterprise remote-access gateways.
An unauthenticated HTTPS request reaches loopback CouchDB, enables its Erlang query server, derives a DMI-based control credential and uses sed injection to execute a root command.
Rapid7 recorded uid=0 on a stock SMA8200v.
The module's failed test against build 12.4.3-02401 means not every older build is demonstrated chainable; the vendor has published fixed branch boundaries.
Dell ThinOS 10, the embedded operating system deployed across Dell thin-client endpoint fleets.
A reachable ThinOS component passes unauthenticated attacker input into an operating-system command or application-code execution path.
Dell has published patched ThinOS 10 releases.
MikroTik RouterOS, the operating system used by MikroTik routers and wireless network appliances.
Allocator shaping leaves a stale principal pointer in a new /jsproxy session, after which parent-directory components escape the encrypted-URI file namespace.
Today's change establishes that the reachable scope includes root-owned files and credential-containing configuration stores; MikroTik has shipped fixed releases.
Windows MIDI Services, the operating-system MIDI stack on affected Windows installations.
An existing low-privilege process can influence an incorrectly permissioned service resource and obtain SYSTEM-context command execution.
Microsoft has published fixed Windows builds.
FolkPatch, an Android rooting project that patches device kernels with a custom KernelPatch fork.
The app invokes FolkPatch's retained supercall interface with the public hardcoded SuperKey "su," and the kernel executes its requested command as root.
Working code is public, the proposed random-key mitigation was not merged, and no fixed official release was identified.
PAPPL, a C printing-application framework used to expose IPP printing services on Unix-like systems.
On a listener configured for remote jobs, attacker-controlled cupsWidth drives raster loops beyond the heap line buffer allocated for the output width.
The execution path was researcher-demonstrated and a patch is published.
Akana API Platform Policy Manager, an enterprise API-management console operated on customer infrastructure.
A crafted path is interpreted differently by the authentication filter and servlet dispatcher, allowing the request to reach unsandboxed script evaluation.
The route is established through the CNA description and version records, but has no public demonstration.
RubyDoc.info, the hosted service that automatically builds documentation for packages published through RubyGems.
A publisher places a Ruby payload behind a gem-controlled .yardopts file and requests documentation generation, causing the worker to evaluate the package's build configuration.
The September 11 report identified more than one hundred public packages using this execution path and preserved payload examples.
RubyDoc.info's current patch state is unknown.
Qualcomm Bluetooth controller firmware spanning mobile, compute, audio, fixed-wireless, XR and networking chipsets.
A nearby device supplies a channel map with too few used channels while adaptive frequency hopping is fully enabled, triggering a controller buffer over-read.
The established result is temporary Bluetooth unavailability, not code execution or persistent compromise.
Qualcomm shared corrected proprietary code with customers, but end-user OEM firmware availability is not established.
Microsoft Defender Malware Protection Engine, the built-in antimalware engine on supported Windows clients and servers.
The repository combines Cloud Filter hydration, Object Manager links and an NTFS reparse point and claims arbitrary file read as SYSTEM with a path toward SYSTEM execution.
An independent reproduction reached the redirect pipeline, but SAM, SECURITY and ELAM reads failed before protected-file bytes were returned.
The claimed post-fix capability remains unestablished until the code returns bytes from a protected target and demonstrates any resulting SYSTEM transition.
No additional findings today.
The Windows Boot Manager privilege path remains opaque; the separate UEFI-shell, TPM and U-Boot material did not establish a new validation bypass.
The same brief, every morning. One email a day, nothing else.
fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.