- Becoming any Android app via Zygote command injection TOP NEW
- Bypassing the "run-as" debuggability check on Android via newline injection TOP NEW
- Missing signs: how several brands forgot to secure a key piece of Android TOP NEW
- CVE-2023-4039: GCC's -fstack-protector fails to guard dynamic stack allocations on ARM64 TOP NEW
- Sandboxing ImageIO media parsing in macOS TOP NEW
- In-Memory Execution in macOS: the Old and the New TOP NEW
- The many meanings of "system app" in modern Android TOP NEW
- Uncovering Hidden .NET Assemblies TOP NEW