vulnerability Multiples vulnérabilités dans Roundcube (19 mars 2026) Multiple vulnerabilities have been discovered in Roundcube Webmail, impacting versions 1.5.x through 1.5.14, 1.6.x through 1.6.14, and 1.7.x through 1.7-rc5. These flaws include data confidentiality breaches, SSRF attack… CERT-FR · Mar 19, 2026 Medium CVE-2026-35537CVE-2026-35544CVE-2026-35545roundcubevulnerabilitywebmail
threat-intel Inside Olympic Cybersecurity: Lessons From Paris 2024 to Milan Cortina 2026 This article discusses cybersecurity challenges faced by the Paris 2024 Olympics and Milan Cortina 2026, focusing on lessons learned from Franz Regul, former CISO for the Paris 2024 Games. The piece highlights the immens… Dark Reading · Mar 16, 2026 High FRITBRcybersecurityolympicsthreat intelligence
vulnerability On the Effectiveness of Mutational Grammar Fuzzing This blog post discusses the limitations of mutational grammar fuzzing, a technique used to find bugs in structured languages like XSLT. The primary issue is that while it increases coverage, it doesn't necessarily lead… Google Project Zero · Mar 5, 2026 High
threat-intel Bypassing Administrator Protection by Abusing UI Access Google Project Zero researchers have identified a significant bypass in Windows' Administrator Protection feature, a security enhancement designed to prevent privilege escalation. The core issue stems from the UI Access… Google Project Zero · Feb 12, 2026 High uacprivilege escalationsecurity vulnerability
vulnerability Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529 Researchers at Google Project Zero discovered and exploited a type confusion vulnerability (CVE-2024-54529) within the coreaudiod system daemon in macOS. The vulnerability, stemming from a double-free, allowed for heap m… Google Project Zero · Jan 30, 2026 Critical CVE-2024-54529CVE-2025-31235macosvulnerabilityheap
threat-intel Bypassing Windows Administrator Protection Microsoft has introduced Administrator Protection in Windows 11 to replace UAC, aiming to create a more secure boundary for administrator privileges. However, research by Google Project Zero revealed nine separate vulner… Google Project Zero · Jan 26, 2026 High uacadministratorbypass
vulnerability A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here? Project Zero researchers discovered a 0-click exploit chain targeting the Pixel 9 and other Android devices, leveraging a vulnerability in the Dolby UDC audio codec. The exploit chain, requiring only two software defects… Google Project Zero · Jan 14, 2026 High CVE-2025-54957CVE-2025-369340-clickaudiodriver
supply-chain A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave A Google Project Zero researcher discovered a 0-click exploit chain targeting the Pixel 9, leveraging a BigWave hardware accelerator and a vulnerability in the mediacodec SELinux context. The exploit bypasses sandboxing… Google Project Zero · Jan 14, 2026 Critical kernelsupply-chainarbitrary-read-write
vulnerability A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby Google Project Zero discovered a 0-click exploit chain targeting the Dolby Unified Decoder (UDC) within the Google Messages app on Pixel 9 devices. The vulnerability stems from a buffer overrun and a memory leak, allowin… Google Project Zero · Jan 14, 2026 High CVE-2025-49415CVE-2025-54957CVE-2025-369340-clickbuffer overflowmemory leak
vulnerability Welcome to the new Project Zero Blog Project Zero has revived older research to highlight the ongoing need for zero-day defenses. The blog post focuses on past exploitation techniques, specifically a 2016 article detailing race conditions in Windows path lo… Google Project Zero · Dec 16, 2025 Medium vulnerabilitywindowsexploitation