It defeats the guarantee that a signed, lockdown-active GRUB image executes only signed native code, and no patch is available.
A lockdown-permitted serial command can erase the bootloader’s authoritative verifier list.
Ubuntu's Canonical-signed GNU GRUB EFI bootloader for x86-64 Linux systems, confirmed in an enforcing QEMU/OVMF Secure Boot VM.
Unsigned native GRUB module execution inside a signed, lockdown-active bootloader
The result is unsigned native execution inside a signed bootloader whose lockdown state still appears intact.
The attacker must control a GRUB configuration source the target accepts without authenticating it, select that boot path, and know the loaded-image placement. An attacker-selected serial MMIO base then redirects fixed UART initialization stores onto grub_file_verifiers and clears the list head.
The public repository supplies the configuration, marker-module generator, hashes, controls and console evidence for three enforcing QEMU/OVMF runs.
There is no patch. We do not have physical-hardware or cross-distribution reproduction, and no vendor acknowledgement is held.
FomoPeek, a cryptocurrency-portfolio application installed on iPhones and iPads.
After the victim installs and launches FomoPeek 1.1 or 1.2, the framework fingerprints the device, selects a compatible kernel path, escapes the sandbox, and reaches other applications’ files and Keychain material without another prompt.
The held evidence is secondary reporting and does not identify the vulnerabilities or the path used on each iOS release.
The Linux kernel ESP-in-TCP and strparser paths used by standard distribution kernels.
The race rearms timer work after teardown cancellation, reclaims the freed context with controlled user-key data, and uses timer expiry for a controlled 64-bit write aimed at modprobe_path.
The exploit needs build-specific offsets and timing; its published material is CentOS-specific, was not independently reproduced here, and does not establish current upstream patch status.
Supported Google Pixel phones running the affected cellular-modem firmware.
Hostile cellular traffic can reach the vulnerable authorization logic without credentials or user interaction and bypass permission checks in the modem context.
Google has published a fix, but pre-fix firmware remains accepted.
Public evidence does not tell us whether the observed chain crosses into the Android application processor or persists beyond the modem.
Suricata, the open-source IDS/IPS and network-security-monitoring engine commonly deployed inline or passively on Linux.
One path uses DoH2 state confusion to produce an invalid free; the other leaves HTTP/2 inspection holding storage that selected response-header rules have freed or reallocated.
OISF patched both failures.
No held source demonstrates reliable crashing, allocation control or code execution.
Claude Code, Anthropic's cross-platform local coding agent and plugin host.
The demonstrated chain combines an installed plugin, repository control, a marketplace repin, a Git backend that permits a SHA-shaped branch, and background updates; the updater accepted that branch without checking that HEAD matched the pinned commit.
AIR reports a working demonstration and verification of the fix in Claude Code 2.1.179.
Codex CLI, OpenAI's cross-platform local coding agent and plugin host.
The demonstrated chain combines an installed plugin, repository control, a marketplace repin, a Git backend that permits a SHA-shaped branch, and background updates; Codex accepted a resolved HEAD that differed from the pinned commit.
Codex 0.146.0 includes a regression-tested fix, and AIR reports verifying it against the end-to-end demonstration.
REDCap, self-hosted research-data capture and public-survey servers used by healthcare and academic institutions.
Public-survey passthrough routing can reach an unintended Data Import controller, where an attacker-controlled path or stream parameter enters code generation.
Fixed releases exist, but the held evidence is the CNA record rather than an independent public reproducer.
TP-Link Tapo C120 and C200 consumer IP security cameras running vulnerable firmware.
With only LAN access to TCP 443, the attacker asks the camera for authentication material, replays it through another request path, and receives an administrator token without the password.
OPSWAT demonstrated the bypass, and TP-Link has published fixed firmware.
Keycloak, an identity-and-access-management server, including Red Hat Build of Keycloak and Red Hat Single Sign-On deployments.
In realms that map administration through a group, a manage-users session can add its own account because the REST endpoint does not evaluate the roles inherited from that group.
No fixed release or generally applicable mitigation has been published.
Check Point Quantum Security Management and Log Servers, including Multi-Domain and standalone deployments that manage network-security policy.
An address admitted by Trusted Clients can send an oversized username before authentication and corrupt the stack of the root-running FWM process.
A patch exists, but controlled root execution has not been demonstrated in the held public evidence.
IBM Guardium Data Protection, a Linux-based database-security and activity-monitoring appliance.
Two network-reachable paths pass insufficiently neutralized shell metacharacters into operating-system commands without requiring credentials or interaction.
IBM has shipped a FixPack for the affected version.
Apple MobileAccessoryUpdater, the accessory-firmware update service used across macOS, iOS, and iPadOS.
A malformed update asset makes uarpd allocate 64 bytes and copy 320 attacker-controlled bytes, overwriting 256 adjacent bytes.
Apple has published a fix.
The public demonstration covers corruption on macOS, not code execution, unpaired reachability, or reproduction on iOS and iPadOS.
SolarWinds Access Rights Manager, Windows-hosted identity and access-rights administration servers and collectors.
An adjacent host can use the product-wide key to cross a trusted component-communication boundary and reach code execution in the service context.
SolarWinds identifies 2026.2.1 as the security release.
LMDeploy, an AI-model deployment and inference-serving framework, when using its PyTorch DistServe or prefill/decode-disaggregation control plane.
On a relevant deployment left at its documented no-API-key default, an unauthenticated caller supplies a ZeroMQ address and returns a malicious pickle object over the resulting outbound connection.
Fixed versions are identified, but no public exploit demonstration is held.
Android phones on which the RatHat APK is installed and granted Accessibility Service control.
After sideloading and an Accessibility grant, RatHat enables Wireless Debugging, reads its pairing code and port, and self-pairs an embedded ADB client.
Its native payloads remain after APK removal, can reinstall the app, and read raw input events containing the unlock PIN or pattern; no platform patch is available.
Zephyr RTOS IPv6 networking, used by embedded and constrained devices including mesh-network nodes.
A link-local attacker sends an unrecognized next-header packet to ff02::1 with a spoofed victim source, and missing suppression checks make each affected node return an ICMPv6 error to the victim.
The upstream fix adds the missing checks at the shared error-sending path.
Linux kernel Bluetooth central hosts, demonstrated with a BCM43438 controller.
A rejected second connection can remain in BT_CONNECT, causing every later outgoing LE connection to return EBUSY until the adapter is reset; upstream reports normal connections after the fix.
The reproduction uses two peers polled together, and it does not establish that an unauthenticated nearby device can create the required pending identities on an ordinarily configured host.
Linux kernel Bluetooth hosts using the affected L2CAP teardown path.
Unlocked access to hci_conn::l2cap_data can race with deletion of its l2cap_conn during disconnect-timeout work; an upstream patch is available.
No public source establishes that a nearby peer can reliably schedule the race or turn it into controlled corruption.
No publishable Wi-Fi capability delta was established, but unavailable hostap logs and the NAN cancellation diff prevent a clean closure.
The Defender repair bypass and RustyTux kernel-write code materially advanced two previously uncertain primitives.
The same brief, every morning. One email a day, nothing else.
fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.