important1 finding, 18 signals, 4 noted6 min read

A hash-pinned Canonical-signed GRUB image can execute an unsigned native module while Secure Boot lockdown continues to report enabled.

It defeats the guarantee that a signed, lockdown-active GRUB image executes only signed native code, and no patch is available.

Priority findings1
§
High
Boot chain
Confirmed

A Canonical-signed GRUB can execute unsigned native code while lockdown still reports enabled.

A lockdown-permitted serial command can erase the bootloader’s authoritative verifier list.

Affects

Ubuntu's Canonical-signed GNU GRUB EFI bootloader for x86-64 Linux systems, confirmed in an enforcing QEMU/OVMF Secure Boot VM.

What it enables

Unsigned native GRUB module execution inside a signed, lockdown-active bootloader

Control a GRUB configuration source that the target accepts without authenticating the configuration and select that boot path.Boot the hash-pinned Canonical-signed gcdx64.efi image through an admitted shim/SBAT path.Use the lockdown-available gdbinfo command to verify the expected image placement.Configure the serial command with a 64-bit MMIO base targeting grub_file_verifiers.Trigger serial input initialization, whose fixed UART stores clear the verifier-list head.Load and execute an unsigned native GRUB module while lockdown continues to report y.
Why this matters

The result is unsigned native execution inside a signed bootloader whose lockdown state still appears intact.

Detail, proof-of-concept code and 6 sources
Required access

Control of a GRUB configuration source accepted without configuration authentication, ability to select that boot path, and knowledge of the exact loaded-image placement; demonstrated in QEMU/OVMF

Affected versions

Ubuntu grub-efi-amd64-signed 1.215+2.14-2ubuntu1, gcdx64.efi.signed SHA-256 dc505a15c1bd97878eede212a052a1bfb2f610176a5401a3679877c536fdcd62

Proof of concept

Public exploit code

The attacker must control a GRUB configuration source the target accepts without authenticating it, select that boot path, and know the loaded-image placement. An attacker-selected serial MMIO base then redirects fixed UART initialization stores onto grub_file_verifiers and clears the list head.

The public repository supplies the configuration, marker-module generator, hashes, controls and console evidence for three enforcing QEMU/OVMF runs.

There is no patch. We do not have physical-hardware or cross-distribution reproduction, and no vendor acknowledgement is held.

Evidence
Reporter reproduced unsigned native-module execution in three enforcing QEMU/OVMF runs against a hash-pinned signed imagePublic repository contains the exact GRUB configuration, marker-module generator, hashes, controls, and console evidencePhysical-hardware reproductionCross-build or cross-distribution reproductionVendor acknowledgement or shipped fix
Share this finding
Signals18
important · Mobile — iOS

A trojanized iOS app carried an automatic eight-exploit kernel framework for sandbox escape and Keychain theft.

Affects

FomoPeek, a cryptocurrency-portfolio application installed on iPhones and iPads.

After the victim installs and launches FomoPeek 1.1 or 1.2, the framework fingerprints the device, selects a compatible kernel path, escapes the sandbox, and reaches other applications’ files and Keychain material without another prompt.

Detail and 2 sources
Chain to watch
Install and launch FomoPeek 1.1 or 1.2Select a device-compatible kernel exploitEscape the sandbox and steal cross-application secretsThe eight vulnerabilities and their per-release exploit mapping remain unidentified.
Unverified chainObtain the complete SlowMist and OKX sample report, exploit-module hashes, or a first-party mapping to fixed iOS releases.

The held evidence is secondary reporting and does not identify the vulnerabilities or the path used on each iOS release.

important · Privilege — Linux

Public RustyTux code turns an ESP-in-TCP race into a controlled kernel write and an attempted root shell.

Affects

The Linux kernel ESP-in-TCP and strparser paths used by standard distribution kernels.

The race rearms timer work after teardown cancellation, reclaims the freed context with controlled user-key data, and uses timer expiry for a controlled 64-bit write aimed at modprobe_path.

Detail and 1 source

The exploit needs build-specific offsets and timing; its published material is CentOS-specific, was not independently reproduced here, and does not establish current upstream patch status.

Chain to watch
Race ESP-in-TCP parsing against teardownReclaim the freed context with controlled dataTurn stale timer execution into a kernel write against modprobe_pathPortability beyond the supplied CentOS target and current upstream remediation remain unresolved.
Unverified chainReproduce on current distribution kernels, then identify the fixing commit or confirm continued reachability.
important · Mobile — Pixel

Google says a no-interaction Pixel modem privilege escalation is under targeted exploitation.

Affects

Supported Google Pixel phones running the affected cellular-modem firmware.

Hostile cellular traffic can reach the vulnerable authorization logic without credentials or user interaction and bypass permission checks in the modem context.

Detail and 3 sources

Google has published a fix, but pre-fix firmware remains accepted.

Chain to watch
Deliver attacker-controlled cellular trafficBypass modem permission checksEscalate privileges in the modem contextAn application-processor pivot or persistence has not been established.
Unverified chainObtain incident-chain evidence or a firmware diff that identifies the resulting execution context and any application-processor transition.

Public evidence does not tell us whether the observed chain crosses into the Android application processor or persists beyond the modem.

important · Network sensor

Traffic crossing Suricata can corrupt the sensor through two unauthenticated HTTP/2 memory-safety failures.

Affects

Suricata, the open-source IDS/IPS and network-security-monitoring engine commonly deployed inline or passively on Linux.

One path uses DoH2 state confusion to produce an invalid free; the other leaves HTTP/2 inspection holding storage that selected response-header rules have freed or reallocated.

Detail and 5 sources

OISF patched both failures.

Chain to watch
Send a flow through the inspected pathTrigger invalid-free or use-after-free conditionsCorrupt the Suricata inspection processDeterministic process takeover remains unproven.
Unverified chainReplay both trigger classes against ASAN and packaged binaries, then measure reliability, allocator control and process containment.

No held source demonstrates reliable crashing, allocation control or code execution.

important · Developer tools — Claude Code

A repository takeover could turn a Claude Code background plugin update into developer-context code execution.

Affects

Claude Code, Anthropic's cross-platform local coding agent and plugin host.

The demonstrated chain combines an installed plugin, repository control, a marketplace repin, a Git backend that permits a SHA-shaped branch, and background updates; the updater accepted that branch without checking that HEAD matched the pinned commit.

Detail and 4 sources
important · Developer tools — Codex

A repository takeover could turn a Codex background plugin update into developer-context code execution.

Affects

Codex CLI, OpenAI's cross-platform local coding agent and plugin host.

The demonstrated chain combines an installed plugin, repository control, a marketplace repin, a Git backend that permits a SHA-shaped branch, and background updates; Codex accepted a resolved HEAD that differed from the pinned commit.

Detail and 5 sources
important · RCE — REDCap

A public REDCap survey hash can expose unauthenticated server-side code execution.

Affects

REDCap, self-hosted research-data capture and public-survey servers used by healthcare and academic institutions.

Public-survey passthrough routing can reach an unintended Data Import controller, where an attacker-controlled path or stream parameter enters code generation.

Detail and 1 source

Fixed releases exist, but the held evidence is the CNA record rather than an independent public reproducer.

important · Firmware — Tapo

A local-network peer can replay camera-supplied material to obtain a Tapo administrator session.

Affects

TP-Link Tapo C120 and C200 consumer IP security cameras running vulnerable firmware.

With only LAN access to TCP 443, the attacker asks the camera for authentication material, replays it through another request path, and receives an administrator token without the password.

Detail and 2 sources
important · Identity — Keycloak

A delegated Keycloak user administrator can promote itself to realm administrator through group membership.

Affects

Keycloak, an identity-and-access-management server, including Red Hat Build of Keycloak and Red Hat Single Sign-On deployments.

In realms that map administration through a group, a manage-users session can add its own account because the REST endpoint does not evaluate the roles inherited from that group.

Detail and 2 sources

No fixed release or generally applicable mitigation has been published.

important · Management plane — Check Point

A pre-authentication FWM login overflow may execute code as root on Check Point management servers.

Affects

Check Point Quantum Security Management and Log Servers, including Multi-Domain and standalone deployments that manage network-security policy.

An address admitted by Trusted Clients can send an oversized username before authentication and corrupt the stack of the root-running FWM process.

Detail and 2 sources
Chain to watch
Reach FWM from a Trusted Clients addressOverflow the pre-authentication username stack bufferAttempt controlled execution in the root processControlled root execution remains unproven.
Unverified chainPublish a reproducer that demonstrates controlled instruction flow or a benign command under the FWM process.

A patch exists, but controlled root execution has not been demonstrated in the held public evidence.

important · Database security — Guardium

Unauthenticated callers can execute operating-system commands on IBM Guardium Data Protection 12.2.

Affects

IBM Guardium Data Protection, a Linux-based database-security and activity-monitoring appliance.

Two network-reachable paths pass insufficiently neutralized shell metacharacters into operating-system commands without requiring credentials or interaction.

Detail and 1 source
important · Bluetooth — Apple

A connected Bluetooth accessory can drive a 256-byte heap overwrite in Apple’s accessory-update daemon.

Affects

Apple MobileAccessoryUpdater, the accessory-firmware update service used across macOS, iOS, and iPadOS.

A malformed update asset makes uarpd allocate 64 bytes and copy 320 attacker-controlled bytes, overwriting 256 adjacent bytes.

Detail and 2 sources

Apple has published a fix.

Chain to watch
Connect an attacker-controlled accessoryDeliver a malformed update assetOverwrite adjacent uarpd heap memoryCode execution and reachability from an unpaired accessory remain unproven.
Unverified chainTest pairing requirements and overwrite control across macOS, iOS and iPadOS.

The public demonstration covers corruption on macOS, not code execution, unpaired reachability, or reproduction on iOS and iPadOS.

important · Enterprise — SolarWinds ARM

A shared static key lets an adjacent unauthenticated host execute code on SolarWinds Access Rights Manager.

Affects

SolarWinds Access Rights Manager, Windows-hosted identity and access-rights administration servers and collectors.

An adjacent host can use the product-wide key to cross a trusted component-communication boundary and reach code execution in the service context.

Detail and 1 source

SolarWinds identifies 2026.2.1 as the security release.

important · AI serving — LMDeploy

LMDeploy DistServe can connect to an attacker-controlled ZeroMQ peer and unpickle code as its serving process.

Affects

LMDeploy, an AI-model deployment and inference-serving framework, when using its PyTorch DistServe or prefill/decode-disaggregation control plane.

On a relevant deployment left at its documented no-API-key default, an unauthenticated caller supplies a ZeroMQ address and returns a malicious pickle object over the resulting outbound connection.

Detail and 1 source
important · Mobile — Android

Accessibility-granted RatHat turns local Wireless ADB into an uninstall-resistant shell that can recover the screen lock.

Affects

Android phones on which the RatHat APK is installed and granted Accessibility Service control.

After sideloading and an Accessibility grant, RatHat enables Wireless Debugging, reads its pairing code and port, and self-pairs an embedded ADB client.

Detail and 3 sources

Its native payloads remain after APK removal, can reinstall the app, and read raw input events containing the unlock PIN or pattern; no platform patch is available.

important · Embedded — Zephyr

One adjacent IPv6 packet can turn every affected Zephyr node on a link into a reflector.

Affects

Zephyr RTOS IPv6 networking, used by embedded and constrained devices including mesh-network nodes.

A link-local attacker sends an unrecognized next-header packet to ff02::1 with a spoofed victim source, and missing suppression checks make each affected node return an ICMPv6 error to the victim.

Detail and 1 source
important · Bluetooth — Linux

Two overlapping outgoing BLE connections can wedge Linux Bluetooth until adapter reset.

Affects

Linux kernel Bluetooth central hosts, demonstrated with a BCM43438 controller.

A rejected second connection can remain in BT_CONNECT, causing every later outgoing LE connection to return EBUSY until the adapter is reset; upstream reports normal connections after the fix.

Detail and 1 source
Chain to watch
Queue two overlapping outgoing LE connectionsLeave the rejected connection stuck in BT_CONNECTBlock later outgoing BLE connections until resetNearby unauthenticated reachability from a stock configuration is unproven.
Unverified chainRepeat with two attacker-controlled advertisers and no pre-provisioned peers across common controllers.

The reproduction uses two peers polled together, and it does not establish that an unauthenticated nearby device can create the required pending identities on an ordinarily configured host.

important · Bluetooth — Linux kernel

Linux can dereference freed L2CAP state during concurrent Bluetooth teardown.

Affects

Linux kernel Bluetooth hosts using the affected L2CAP teardown path.

Unlocked access to hci_conn::l2cap_data can race with deletion of its l2cap_conn during disconnect-timeout work; an upstream patch is available.

Detail and 1 source
Chain to watch
Begin L2CAP teardown during disconnect-timeout workDelete the referenced l2cap_connDereference the freed statePeer-driven scheduling and controlled corruption remain unproven.
Unverified chainReproduce through a real controller under KASAN, vary peer-driven disconnect timing, and groom the freed allocation.

No public source establishes that a nearby peer can reliably schedule the race or turn it into controlled corruption.

Also noted4
Physical — Apple
Apple fixed a Siri Suggestions flaw that exposed sensitive information from a locked iPhone or iPad.
Treat it as a physical-access information leak; Apple has not disclosed the triggering interaction or exposed data classes.
ResearchAbout the security content of iOS 26.7 and iPadOS 26.7 - Apple Support
Bluetooth — Apple
Apple widened a previously known macOS Bluetooth authorization bypass to five more operating-system families.
A local app could access Bluetooth without authorization; fixes are available, but no public demonstration is held.
ResearchAbout the security content of iOS 27 and iPadOS 27 - Apple Support
Firmware — D-Link
Public DIR-868L code moves an unauthenticated LAN request from stack overflow to attacker-selected program-counter control.
There is no patch, but stable code execution on stock physical hardware remains unproven.
SecondaryCVE-2026-94089: unauthenticated D-Link DIR-868L authentication-handler overflow
Firmware — Netcore
A new record says the NBR200V2 diagnostic CGI accepts unauthenticated operating-system command injection.
There is no patch; default WAN exposure, process identity and the originating demonstration remain unavailable.
SecondaryCVE-2026-94097: unauthenticated command injection in Netcore NBR200V2 diagnostics
What was checked · 2 quiet
Wi-FiQuiet

No publishable Wi-Fi capability delta was established, but unavailable hostap logs and the NAN cancellation diff prevent a clean closure.

ResearchQuiet

The Defender repair bypass and RustyTux kernel-write code materially advanced two previously uncertain primitives.

Get it by email

The same brief, every morning. One email a day, nothing else.

fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 21, 2026