Full Disclosure A public, vendor-neutral forum for detailed discussion of vulnerabilities and exploitation techniques, as well as tools, papers, news, and events of interest to the community. The relaxed atmosphere of this quirky list provides some comic relief and certain industry gossip. More importantly, fresh vulnerabilities sometimes hit this list many hours or days before they pass through the Bugtraq moderation queue.
- [REVIVE-SA-2025-004] Revive Adserver Vulnerabilitieson November 19, 2025 at 8:03 pm
Posted by Matteo Beccati on Nov 19======================================================================== Revive Adserver Security Advisory REVIVE-SA-2025-004 ———————————————————————— https://www.revive-adserver.com/security/revive-sa-2025-004 ———————————————————————— Date: 2025-11-19 Risk Level: Medium Applications affected: Revive…
- [REVIVE-SA-2025-003] Revive Adserver Vulnerabilitieson November 19, 2025 at 8:03 pm
Posted by Matteo Beccati on Nov 19======================================================================== Revive Adserver Security Advisory REVIVE-SA-2025-003 ———————————————————————— https://www.revive-adserver.com/security/revive-sa-2025-003 ———————————————————————— Date: 2025-11-05 Risk Level: High Applications affected: Revive…
- [SYSS-2025-059]: Dell computer UEFI boot protection bypasson November 19, 2025 at 8:03 pm
Posted by Micha Borrmann via Fulldisclosure on Nov 19Advisory ID: SYSS-2025-059 Product: Dell computer Manufacturer: Dell Affected Version(s): Probably all Dell computers Tested Version(s): Latitude 5431 (BIOS 1.33.1), Latitude 7320 (BIOS 1.44.1), Latitude 7400 (BIOS 1.41.1), Latitude 7480 (BIOS 1.41.3), Latitude 9430 (BIOS…
- Re: [FD] : “Glass Cage” β Zero-Click iMessage β Persistent iOS Compromise + Bricking (CVE-2025-24085 / 24201, CNVD-2025-07885)on November 14, 2025 at 2:03 am
Posted by Patrick via Fulldisclosure on Nov 13Hello Jan, You are completely right and itβs something I warned about early, which is abuse of AI-generated sensationalized headline and fake PoC-s, for fame. I urge the Full Disclosure staff to look into it. Discussions with the individual responsible seem to be fruitless, and this likely constitutes abuse of this mailing list. Sent from Proton Mail for iOS. ——– Original Message ——– I looked at few repos and posts of…
- APPLE-SA-11-13-2025-1 Compressor 4.11.1on November 14, 2025 at 2:02 am
Posted by Apple Product Security via Fulldisclosure on Nov 13APPLE-SA-11-13-2025-1 Compressor 4.11.1 Compressor 4.11.1 addresses the following issues. Information about the security content is also available at https://support.apple.com/125693. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. Compressor Available for: macOS Sequoia 15.6 and later Impact: An unauthenticated user on the same network as a Compressor…
- Re: 83 vulnerabilities in Vasion Print / PrinterLogicon November 14, 2025 at 2:02 am
Posted by Pierre Kim on Nov 13No message preview for long message of 668188 bytes.
- Re: [FD] : “Glass Cage” β Zero-Click iMessage β Persistent iOS Compromise + Bricking (CVE-2025-24085 / 24201, CNVD-2025-07885)on November 7, 2025 at 1:49 pm
Posted by Joseph Goydish II via Fulldisclosure on Nov 07Hey Patrick, I understand the doubt. Howeverβ¦ whatβs not slop is reproducible logs I provided a video of and the testable, working exploit I provided. Neither is the upstream patches that can be tracked from the disclosure dates to the cveβs listed in the report. The exploit was caught in the wild, reversed engineered via log analysis and the logs provided are simply observed behavior. Please feel free to independently test the…
- Re: : “Glass Cage” β Zero-Click iMessage β Persistent iOS Compromise + Bricking (CVE-2025-24085 / 24201, CNVD-2025-07885)on November 7, 2025 at 1:49 pm
Posted by Jan Schermer on Nov 07I looked at few repos and posts of “Joseph Goydish”. It all seems to be thinly veiled AI slop and BS. Cited vulns are not attributed to him really and those chains donβt make a lot of sense. Screen recordings look suspicious, some versions reference High Sierra for some reason (but I canβt find those bits now). I invite anyone to look at his GH repos and scroll through commit history. Does this make any sense?…
- runc container breakouts via procfs writes: CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881on November 7, 2025 at 1:45 pm
Posted by Aleksa Sarai via Fulldisclosure on Nov 07| NOTE: This advisory was sent to <security-announce () opencontainers org> | on 2025-10-16. If you ship any Open Container Initiative software, we | highly recommend that you subscribe to our security-announce list in | order to receive more timely disclosures of future security issues. | The procedure for subscribing to security-announce is outlined here: | <…
- OXAS-ADV-2025-0002: OX App Suite Security Advisoryon November 7, 2025 at 1:45 pm
Posted by Martin Heiland via Fulldisclosure on Nov 07Dear subscribers, We’re sharing our latest advisory with you and like to thank everyone who contributed in finding and solving those vulnerabilities. Feel free to join our bug bounty programs for OX App Suite, Dovecot and PowerDNS at YesWeHack. This advisory has also been published at https://documentation.open-xchange.com/appsuite/security/advisories/html/2025/oxas-adv-2025-0002.html. Yours sincerely, Martin Heiland, Open-Xchange…
- APPLE-SA-11-05-2025-1 iOS 18.7.2 and iPadOS 18.7.2on November 7, 2025 at 1:44 pm
Posted by Apple Product Security via Fulldisclosure on Nov 07APPLE-SA-11-05-2025-1 iOS 18.7.2 and iPadOS 18.7.2 iOS 18.7.2 and iPadOS 18.7.2 addresses the following issues. Information about the security content is also available at https://support.apple.com/125633. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. Accessibility Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation…
- APPLE-SA-11-03-2025-9 Xcode 26.1on November 7, 2025 at 1:44 pm
Posted by Apple Product Security via Fulldisclosure on Nov 07APPLE-SA-11-03-2025-9 Xcode 26.1 Xcode 26.1 addresses the following issues. Information about the security content is also available at https://support.apple.com/125641. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. GNU Available for: macOS Sequoia 15.6 and later Impact: Processing a maliciously crafted file may lead to heap corruption Description: An…
- APPLE-SA-11-03-2025-8 Safari 26.1on November 7, 2025 at 1:44 pm
Posted by Apple Product Security via Fulldisclosure on Nov 07APPLE-SA-11-03-2025-8 Safari 26.1 Safari 26.1 addresses the following issues. Information about the security content is also available at https://support.apple.com/125640. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. Safari Available for: macOS Sonoma and macOS Sequoia Impact: Visiting a malicious website may lead to address bar spoofing Description:…
- APPLE-SA-11-03-2025-7 visionOS 26.1on November 7, 2025 at 1:44 pm
Posted by Apple Product Security via Fulldisclosure on Nov 07APPLE-SA-11-03-2025-7 visionOS 26.1 visionOS 26.1 addresses the following issues. Information about the security content is also available at https://support.apple.com/125638. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. Apple Account Available for: Apple Vision Pro (all models) Impact: A malicious app may be able to take a screenshot of sensitive…
- APPLE-SA-11-03-2025-6 watchOS 26.1on November 7, 2025 at 1:44 pm
Posted by Apple Product Security via Fulldisclosure on Nov 07APPLE-SA-11-03-2025-6 watchOS 26.1 watchOS 26.1 addresses the following issues. Information about the security content is also available at https://support.apple.com/125639. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. Apple Account Available for: Apple Watch Series 6 and later Impact: A malicious app may be able to take a screenshot of sensitive…





