CWE-787

CVE-2026-86924: A Bluetooth Heap Overflow in uarpd

A malformed Bluetooth accessory update made uarpd copy five times more data than it allocated. Apple fixed the heap overflow and assigned CVE-2026-86924.

CVE-2026-86924BluetoothmacOSMemory Corruption
Critical CWE-639

Two Dots to Admin: A $50K Account Takeover on Apple

A single encoded dot-dot slipped past the authorization check and let me read any account's private data with one request, then make myself an admin with another. Here is how the bug worked.

IDORAuthorization BypassPath TraversalAPI SecurityCWE-639
Critical CWE-918

Pre-Auth Full Read SSRF Leaking AWS Keys via Redirect Bypass

A critical pre-auth SSRF that slipped past the backend's filters with an open redirect and handed back live EC2 credentials. No login required.

SSRFAWSCloudCWE-918