Tagged articles

sandbox escape

5 articles · Page 1 of 1
Black & White Path
Black & White Path
Aug 2, 2026 · Information Security

How a Simple "Hello World" Flatpak App Escapes the PipeWire Sandbox to Execute Arbitrary Code

The analysis of CVE‑2026‑5674 reveals that PipeWire’s PulseAudio compatibility layer contains three independent flaws—a missing cookie verification, default‑enabled module loading, and unrestricted dlopen() paths—that together let a sandboxed Flatpak app with only audio permission write files, launch desktop applications, and run arbitrary code on the host.

CVE-2026-5674FlatpakPipeWire
0 likes · 15 min read
How a Simple "Hello World" Flatpak App Escapes the PipeWire Sandbox to Execute Arbitrary Code
Black & White Path
Black & White Path
Jul 11, 2026 · Information Security

How an AI‑Assisted Frida Workflow Uncovered Six Android Zero‑Days

The article details how bounty hunter ynsmroztas leveraged an AI‑enhanced, non‑root Android penetration testing framework called AndroScope—built on Frida Gadget—to automate a PREPARE‑ASSESS‑RUNTIME workflow, discover six new Android zero‑day vulnerabilities, and highlight sandbox‑escape techniques as high‑value targets.

AI-assisted Vulnerability DiscoveryAndroScopeAndroid Security
0 likes · 10 min read
How an AI‑Assisted Frida Workflow Uncovered Six Android Zero‑Days
Black & White Path
Black & White Path
Jun 16, 2026 · Information Security

Low‑Privileged User Can Hijack LiteLLM AI Gateway via a Three‑Step Exploit Chain

The article details a three‑vulnerability chain (CVE‑2026‑47101, CVE‑2026‑47102, CVE‑2026‑40217) in the open‑source LiteLLM AI gateway that lets a default low‑privilege account bypass authorization, elevate to proxy_admin, escape the sandbox and execute arbitrary code, exposing master keys, provider credentials and all traffic through the gateway.

CVE-2026-40217CVE-2026-47101CVE-2026-47102
0 likes · 9 min read
Low‑Privileged User Can Hijack LiteLLM AI Gateway via a Three‑Step Exploit Chain
Black & White Path
Black & White Path
Apr 18, 2026 · Information Security

iExploit Lab v1.0: $20K Dark‑Web iOS Exploit Tool Under Scrutiny

A dark‑web listing advertises iExploit Lab v1.0, a purported iOS 13‑17.2 exploit kit priced at $20,000, claiming remote code execution, sandbox escape, privilege escalation, and data theft via a C2 panel, though its authenticity remains unverified.

Dark WebRemote Code Executionexploit kit
0 likes · 2 min read
iExploit Lab v1.0: $20K Dark‑Web iOS Exploit Tool Under Scrutiny
ITPUB
ITPUB
Sep 25, 2018 · Information Security

How a Security Engineer Hacked a Singapore Hotel Wi‑Fi Server and Got Fined $5,000

A Chinese security engineer exploited default credentials and multiple vulnerabilities in a Singapore hotel’s Wi‑Fi authentication system, gained root access, extracted MySQL data, achieved remote code execution, and was later fined $5,000 by Singapore courts for unauthorized access and password disclosure.

DirtyCOWRemote Code ExecutionWiFi hacking
0 likes · 11 min read
How a Security Engineer Hacked a Singapore Hotel Wi‑Fi Server and Got Fined $5,000