Book a call Start a run

Vulnerabilities V12 found and disclosed. Each story is a thread from @v12sec.

another day, another universal linux LPE

403282.5K542.3K1K

🐬🐬🐬 dolphin rce 🐬🐬🐬

411042.2K205.9K376

today we are releasing a qemu escape

242571.7K330.4K637

AnyPwn: AnyDesk preauth 0click RCE (heap buffer overflow) we will release PoC post disclosure and patch

292341.6K132.3K774

We reported a critical loss of funds bug to @Thorchain (32M TVL, 150M FDV) They silently patched it and told us their bug bounty program is permanently retired. We have more Thorchain chain halt DoS vulns. We intend to release them (open disclosure) in the coming few days

28 April
We have found what is likely a critical vulnerability and wanted to
responsibly disclose it to you.
can share more details
10:39 AM V/
attestation-finality-bypass-patches.Today
Hi
10:59 AM V/
Waiting to hear back from you re: bounty for our critical submission
10:59 AM V/
Can you Imk what the status is pls? 11:00 AM //
I am not aware of any bug boun
981231.3K406.5K278

Stick around on our web page for 10 minutes and all your funds are gone. Just connect your wallet to the dApp and enjoy some Temple Run. Unlock your wallet again and it’s empty 😇. A silent signature extraction in @Rabby_io, leading to a full wallet drain. 🧵

42131967320.7K505

And here's postgres bidirectional RCE no admin required, client infects server, server infects client ♻️🐛

12119936185.8K474

Signal's Contact Discovery automatically sends your contact list information to an SGX enclave in the cloud. V12 broke into that enclave and leaked the key, allowing the server host to decrypt everything. Two separate critical bugs: arbitrary read and RCE. Here's how. 🧵

17151730139.7K344

found another one! redis 8.8.0 bidirectional RCE we will release poc after the patch

19104799225.8K343

Type text into Wikipedia. Get the shell's output back on the page. A bug introduced 22 years ago. Still alive in the wild, until it was found by V12. Here's how EasyTimeline allowed arbitrary code execution (RCE) directly from wikitext.

WIKIPEDIA2
25 years of the free encyclopedia
Main menu
hide
Main page
Contents
Current events
Random article
About Wikipedia
Contact us
Donate
Contribute
Help
Learn to edit
Communi
986663122.5K238

user → root privesc 0-day in CUPS a free PoC while we wait for some bigger disclosures to go through 😇

97153944K250

unauthenticated root RCE on TerraMaster TOS4 NAS appliances. (+free additional LPE) something light for sunday. bigger stuff this week! :-)

858433105.7K153

here's a mariadb RCE, what should we look at next?

134539672.2K130

new fragnesia variant (unpatched)

124739368.6K105

linux LPE in rds kernel module

85636768.1K134

Default configuration of WKWebView can cause downloaded files to instead be rendered on the host page. This allows HTML injection, and sometimes even XSS, in countless iOS and WebKit apps. PlayStation 5. Firefox. X. Instagram. TikTok. Telegram. Binance... Breakdown and POC. 🧵

default 'WKWebView' config causes vulnerabilities
in 30+ popular apps
$10K bounty
$6K bounty
vulnerable
vulnerable
vulnerable
vulnerable
vulnerable
vulnerable
...and many more
55633347.8K236

we have a redis-cli preauth RCE. the poc works on latest (8.8.0) it's been stuck in hackerone triage for 11 days with no activity what should we do?🥺🥺🥺

[*]
groom
[+] groom
staging 1024
reclaim key armed
reclaim values
[*] roles
[+] roles
[*]
prime
[+]
prime
[*] blocker
[*1 prime
[*] trigger
[+] blocker
[*] trigger
[+] trigger
wait
From this thread
15922882.3K39

We collided on this bug! Since this has been disclosed and patched, we're also releasing our POC for DirtyCBC (we called it "DirtyDecrypt").

Post
UE
V12
@v12sec
••.
8054e424466ed2c353b94fb25643e17bef50b31be95038e1c70015635
7e2d74b
5:30 PM • May 9, 2026 • 2,818 Views
C71
0 6
user@MacBook-Pro-7:~/Documents/pocs/dirtydecry323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
/*
*
*/
* Fire one splic
12616828.6K72

firefox focus universal xss 0day (universal account takeover) this is still unpatched after almost a year in disclosure so we are releasing our poc

Arbitrum Nitro normally runs natively, but disputes rely on fraud proofs run in a WASM VM. If these two environments don't fully agree, it can get ugly… like “L1 bridge funds ($2.8B) can be extracted” ugly. Here's how V12 uncovered two independent mismatches, autonomously.

Native
Wasmer JIT
D0
00
00
00
D0
Prover
00
00 00
00
•-
--
--:
20-.00-0
WAVM 0000
DISLREPHUILT
LETELTEI
00
0 0 0 0 ØØ
00
00 00 00 00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
51211311.9K54

🪿🪿🪿 goose rce 🪿🪿🪿

5612011.7K29

XSS to full account takeover and wallet drain in Ditto. V12 found a deeplink parser bug that steals Nostr private keys with just one click. Here's how. 🧵

51310120.8K52
*Spark

Finding a bug in a Bitcoin L2

V12 found and developed a working PoC for a bug in how deposits are handled on Spark, the Bitcoin L2 built by @lightspark. This was done fully autonomously.

248210.4K45

we consistently find bugs human auditors miss in this review for the Ethereum Foundation, we reported a unique High-severity bug. it stems from missing input validation us and the human auditors found the same set of crits

Severity
Critical
High
Medium
Low
Invalid
Classified Bugs
2
2
4
4
6
Found by Human
-
-
M-01, M-02, M-03, M-04
L-01, L-04
I-02, L-04, L-05
Found by Al
-
H-02
-
L-03
L-01 L-03, L-06
336312.7K23

Stored XSS in Forgejo, leading to full control over a victim's account:

110414.6K19

A malicious dApp shows a harmless call. You click Sign. It adds a second transaction, and the wallet signs both. Your account is now empty. V12 found this and four more Ambire Wallet bugs, including one that lets a malicious subdomain sign into a dApp as you. Here’s how:

43283.6K3

Iroh is a P2P networking Rust library used by (among others) Paycode and Nous. We found a preauth DoS in iroh-relay where malformed messages could crash relays. The iroh team fixed it in iroh-relay 1.0.2 and patched public relays. Thanks to @n0computer for the fast response!

12316.6K8

Type to search.