tag
Reverse-Engineering
Ghidra — Swift Demangler Arbitrary Code Execution via Shared Project Files (CVE-2026-18718)
Opening someone else's Ghidra project is enough to execute their code — with no prompt, no signature check, and no integrity verification.
ZXIC/Sanechips ZX297520V3 BootROM Arbitrary Memory Write via USB Download Mode (CVE-2026-40003)
The ZX297520V3 BootROM falls back to a USB download mode when it cannot load or verify a valid image from flash, entering a handshake loop that accepts a stage-1 image over USB for device recovery. The BootROM's image-load command does not validate the…
Windows Shell LNK _IDCONTROLW Zero-Click SMB Coercion Builder — CVE-2026-32202
This repository documents a reverse-engineered, undocumented IDCONTROLW structure used internally by shell32.dll to represent Control Panel applet items inside a .lnk file's LinkTargetIDList, based on the researcher's own IDA Pro static analysis and…
Ghidra 12.1.2 Conditional Swift Demangler ACE (plus TraceRMI RCE and SevenZipJBinding Reachability)
This entry packages three conditional, defensively-scoped findings against Ghidra 12.1.2 rather than a single unconditional exploit. First, the Swift demangler analyzer builds and launches a swift-demangle executable from a program/analyzer-controlled tool…