Twelve CVEs discovered and responsibly disclosed by Pavan Nallamothu, with fixes and credits from Apple, CISA, the NSA, and open-source projects including yt-dlp, AutoGPT, and BlueprintUE. Each entry links to the authoritative cve.org record and, where applicable, the GitHub Security Advisory.
Sandbox file-read via a permissions issue in Apple Type Services, fixed across macOS Tahoe, Sequoia, and Sonoma.
Privilege escalation via unauthorized admin-group assignment.
Cross-project IDOR in the validateCopy endpoint.
Authorization bypass via a URI-normalization differential in the RBAC layer.
Directory traversal in archive extraction (guard/sink mismatch on directory entries).
SSRF via a user-controlled SMTP server, bypassing the IP blocklist.
Dangerous file-type creation via a filename-sanitization bypass (executable-shortcut injection).
Authenticated password change does not verify the current password (account takeover).
Active sessions are not invalidated after a password change or reset.
Missing brute-force protection on login.
Password-reset tokens have no expiry window.