The phone method is proprietary and model-specific. The boot issue affects specialized configurations, and public evidence stops short of recovering and using the original volume’s key.
Five Samsung Exynos 1280 phones and 19 phones using Unisoc T760, T770 or T820 systems-on-chip, as newly supported by Passware Kit Mobile 2026 v5.
The broader release adds passcode recovery and user-data decryption for 24 Android phone models.
This remains secondary because the acquisition route, boot-state requirements, and model-by-model operating-system boundary are not public or independently reproduced.
Apple iPhone devices running iOS, when seized after at least one unlock and connected to Magnet GrayKey Preserve or a GrayKey system with Evidence Preservation Mode.
The claim would extend the forensic-access window indefinitely, but it applies only after the phone has already entered After First Unlock state and the preservation mode is activated.
We do not know the mechanism, supported hardware and iOS boundary, or whether the behavior works on fully updated devices.
Android's privileged Bluetooth service on Android 16, Android 16 QPR2, and Android 17 devices.
The defect is a heap out-of-bounds write in cfg2prop inside the privileged Bluetooth component, and Google classifies the result as remote code execution without user interaction.
The missing fact is the attacker’s starting position: the bulletin does not identify the transport, profile, pairing state, or privileges retained after execution.
Android's privileged Bluetooth service on Android 16, Android 16 QPR2, and Android 17 devices.
Google classifies an uninitialized-pointer path, an AVRCP race, and a snoop-filter validation flaw as local elevation of privilege.
These are secondary because code must already be running locally, and the app-visible entry points, required Bluetooth state, and resulting SELinux boundary remain unpublished.
LibreOffice Calc, the spreadsheet application and headless document converter available across desktop and server platforms.
A saved external-data mapping can select the SQL provider and retrieve a remote JDBC driver during document loading; the driver’s code runs as the LibreOffice process.
The route crosses the document-to-code boundary for desktops and automated document pipelines, but it requires the file to be opened with LibreOffice Java support available.
Samsung Mobile devices running Android 14 through 17 with security software older than the October 2026 maintenance release.
The reported consequence crosses the application privilege boundary, but Samsung does not disclose the invoking IPC route, required permissions, or affected device coverage.
We also do not know whether an ordinary application can reliably control execution after triggering the lifetime error.
HPE Integrated Lights-Out 7, the embedded management controller in HPE ProLiant Gen12 servers.
The affected range is iLO 7 firmware before 1.25.00, and exploitation requires network access but no authenticated management session.
The disclosure does not establish whether success yields an iLO session, Compute Ops Management impersonation, direct server controls, or some narrower effect.
Claude Code, Anthropic's local coding-agent command-line application.
The checked path can be atomically replaced before write-time resolution, causing Claude Code to modify an attacker-selected file with the session user’s authority.
The boundary failure is real but requires an adversarial concurrent workspace writer to win the race.
Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo and Crowd Data Center, plus Crucible and Fisheye; self-managed enterprise collaboration and development servers.
The traversal reaches specifically named files beneath the application web root without authentication across the affected self-managed products.
Its ceiling is narrower than arbitrary filesystem read: the caller must know the exact path, and the disclosed scope ends at the web root.
The Model Context Protocol Python SDK, used to build HTTP-accessible MCP servers.
A caller with a valid sibling-service token can authenticate to an affected MCP HTTP server when the verifier does not enforce the receiving resource as the token audience.
The repair is incomplete by default: upgrading adds resource validation but leaves it disabled until the operator configures it.
Amazon SageMaker Distribution images used by SageMaker Unified Studio Spaces in AWS.
Crafted project connection data reaches an unneutralized shell invocation when another member’s Space validates connections during startup.
The injected command runs in the peer’s Space; when Trusted Identity Propagation is enabled, it can obtain that member’s temporary execution-role credentials for downstream AWS calls.
Promon Shield for Mobile, a commercial runtime self-protection layer embedded in Android banking, payment and game applications.
The demonstrated method extracts protected material after runtime decryption and replaces Shield’s native implementation with compatible JNI behavior that neutralizes active checks.
It requires a copied APK, a rooted device, and skilled app-specific work; it does not cover Promon attestation. Promon reproduced the method and released hardened versions.
Rejetto HFS 3.x, a cross-platform self-hosted HTTP file-sharing server.
Unauthenticated login responses expose consecutive output from the generator used to derive HFS’s cookie-signing key. Recovering that state permits a forged administrator session, after which set_config and server_code execute JavaScript in the server context.
Today’s change is the established generator-state root cause.
Perforce P4 Search, a Windows/Linux search service connected to Helix Core/P4 Server and commonly deployed in containers.
A network peer can use unauthenticated JDWP for code execution as the service account, or obtain top application privilege through a documented default token or a fail-open blank token.
The product’s ordinary same-network placement makes those paths reachable to peers, but the affected service is specialized and fixed releases are available.
Loom for AWS, AWS Labs' self-hosted AI-agent orchestration and management platform.
Before version 1.6.1, the authentication dependency returns a fixed super-admin identity without examining an Authorization header when neither Cognito nor an active external provider is configured.
That identity can control agents and security configuration, invoke agents, register tool servers, export stored integration secrets, and rewrite managed-agent IAM role policies. Public testing reproduced identity acquisition, resource creation, and secret export.
LightLLM, a Linux-based distributed large-model inference server; this path is present on dedicated visual-only multimodal nodes.
The optional visual-only RPyC service binds without an authenticator and enables pickle deserialization; a crafted remote_infer_images argument executes before type handling.
The new scope evidence is second-host reproduction, which establishes a network path rather than only local execution. Exposure remains limited to nodes launched in visual-only mode with the port reachable.
Maestro, a desktop application for controlling development tools and AI agents on Windows, macOS, and Linux
The UUID can be recovered from plaintext LAN traffic, a leaked pairing or sharing URL, a broadly readable local file, or a cross-origin connection to services bound on all interfaces.
Possession of that URL reaches Maestro’s interactive terminal with the user’s authority. The coordinated advisory says mitigations shipped for the exposed bind, bearer credential, cross-origin paths, and file permissions.
TP-Link TL-WR841N v14, an embedded home Wi-Fi router
The path crosses from authenticated web administration into the router’s operating-system command context by incorporating the supplied gateway value into a system command.
It requires LAN access and valid administrator credentials, affects the v14 hardware revision, and has region-specific fixed firmware.
Passware Kit Mobile, a commercial mobile-forensics product for extracting and decrypting locked Android devices.
Passware says Kit Mobile 2026 v5 supports five Exynos 1280 Samsung models; the Galaxy A53 is the only one named publicly in the supplied evidence. With physical custody, the workflow uses model-specific low-level acquisition, offline GPU guessing, and the recovered passcode to decrypt supported data.
We do not know the entry primitive, the other four models, the required boot state, or the exact model and version boundary for MDFPP and SDP. The proprietary method has not been independently reproduced in public.
Linux systems using systemd 262, a Dracut-generated initramfs, TPM2-backed LUKS auto-unlock, and a policy that relies on PCR15 changing from zero before leaving the initramfs.
systemd 262 moved volume-key measurement to systemd-pcrextend.socket. Affected dracut initrds omit that socket; cryptsetup warns but continues, so PCR 15 can remain zero through leave-initrd.
With device custody, an attacker can retain the signed UKI while substituting the root filesystem. A proposed dracut change restores the socket, but affected pre-fix images remain accepted and revocation status is unresolved.
No additional findings today.
No new zero-click primitive survived; the authoritative August Android tables remain unavailable.
iLO 7 validation and narrow router command paths remain constrained by missing exposure or authority details.
The same brief, every morning. One email a day, nothing else.
fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.