Tech News
← Home  ·  All topics

Arbitrary Code Execution

2 GoKawiil briefs on this topic

Apple releases iOS 26.7.1 to patch actively exploited zero-day flaw

Apple has issued iOS 26.7.1 for devices still on iOS 26 or earlier to fix a security vulnerability in its CoreGraphics framework. The company says the flaw may have been exploited in a highly sophisticated attack against specific targeted individuals, and could allow arbitrary code execution. Users on iOS 27 are unaffected but should still install iOS 27.0.1 to stay current.

Qubes OS patches Dom0 code execution flaw in qvm-copy-to-vm tool

Qubes OS disclosed QSB 118, a vulnerability in the qvm-copy-to-vm utility that lets a compromised qube inject arbitrary commands into dom0 when a user copies files to it. The flaw stems from insufficient sanitization of a file name reported back through the qfile protocol's error-reporting mechanism, which dom0 displays without properly neutralizing malicious content. Users are advised to update normally to receive the fix, with no other action required.