A researcher discovered two unpatched flaws in OnePlus's OxygenOS that allow installed apps to gain root access without special permissions. OnePlus confirmed the vulnerabilities affect multiple devices from OnePlus and OPPO but refused to allow disclosure, claiming exclusive control over when flaws become public. After five months without a fix, the researcher published the details on September 24, revealing how the attack chains two OnePlus services to escalate privileges to full system control.
Researchers discovered critical side-channel vulnerabilities in file-notification systems across Linux, Android, Windows, and macOS that allow attackers with read-only access to reconstruct user behavior by monitoring file change notifications. Each platform has unique severe issues: Linux's inotify leaks keystroke timing through directory watches, Android's FileObserver bypasses app storage isolation to reveal private app activity, and Windows exposes system-wide file access across users through directory watching.
A security vulnerability (CVE-2026-55074) was discovered in jailexec, an Ansible plugin for managing FreeBSD jails. The flaw allowed a root process inside a jail to escape and write arbitrary files to the host system by exploiting symlink resolution during file transfers. The vulnerability was fixed in version 2.0.0 released on 2026-06-10.
Muhammad Alifa Ramdhan discovered CVE-2025-39964, a Linux kernel AF_ALG vulnerability enabling unprivileged users to escalate to root through a race condition between socket writers. The flaw, present since 2011, was responsibly disclosed and earned a $113,337 Google kernelCTF reward; it differs from the later Copy Fail vulnerability and can also escape Docker containers.
A researcher discovered two chained vulnerabilities in OnePlus 15 (OxygenOS 16) that allow an untrusted app to gain root access and full Linux capabilities without special permissions. The exploit chains AtlasService's unprotected setEvent binder call with a path traversal in audioDumpInfo to achieve uid 0 execution; OnePlus confirmed the issue affects multiple OnePlus and OPPO devices and has fixed it in version 16.0.10.500(EX01).
Security researchers detail the exploitation of CVE-2025-13032, a double-fetch vulnerability in Avast's kernel driver that leads to a paged pool overflow on Windows 11. By racing a toggled Length field, attackers achieve arbitrary kernel read/write primitives and escalate privileges to SYSTEM via token theft and IORing object corruption.
cPanel disclosed three security flaws, including a critical vulnerability in its CalDAV/CardDAV service that allows any hosting account holder to execute code as root and gain full server control. A second flaw in the WP Toolkit plugin enables users to modify databases belonging to other accounts, while a third permits reading other accounts' calendar data. cPanel has released patched versions for all three issues.
RustyTux is a Linux kernel local privilege-escalation exploit targeting an ESP-in-TCP race condition in the strparser that affects multiple major Linux distributions including CentOS Stream 9 and Ubuntu 26.04 LTS. The timing-sensitive exploit uses x86 prefetch side-channel attacks to leak kernel base addresses and reclaims freed memory to achieve unprivileged privilege escalation.
A blog post describes exploiting CVE-2026-66804, an incomplete fix for the Windows privilege escalation vulnerability CVE-2026-50343 ('Dark Elevator'). The vulnerability involves a dangling COM object registration for CrossDevice with a missing server DLL in a world-writable directory, which attackers can abuse via custom COM marshaling to load arbitrary code into privileged processes.
A zero-day vulnerability in Meta's Muse allows local attackers to redirect dictation traffic by modifying an undocumented endpoint setting, enabling capture of audio, prompt injection, theft of authentication credentials, and abuse of Muse's elevated access privileges. A proof-of-concept tool demonstrates the attack by intercepting dictated prompts sent to an attacker-controlled endpoint.
RustyTux is a Linux kernel local privilege-escalation exploit targeting an ESP-in-TCP use-after-free race condition in the strparser subsystem. The timing-sensitive exploit derives the kernel base via x86 prefetch side-channel, races socket teardown, and reclaims freed memory to escalate privileges. As of September 2026, the vulnerability affects standard kernels in CentOS Stream 9 and Ubuntu 26.04 LTS.