Ghostscript exploit chain pops KDE file manager for unsandboxed RCE from one link click
moyix · x · 2026-09-26
Researcher v12sec published a PoC chaining Ghostscript memory-corruption exploits: a single link click in Chrome downloads a file, and KDE's file manager opening it yields unsandboxed RCE. The author calls it the "full chain from temu."
More from Safety
- Cambridge explores AI to cut regulatory paperwork for medical AI software — lawrennd · 2026-09-26
- Cyber insurers consider limiting coverage as agentic AI hacks defy pricing — rvp · 2026-09-26
- OpenSSF: AI Finds Vulnerabilities Faster Than We Can Fix Them — rvp · 2026-09-26
- Ex-AI researcher explains why the fake-news flood prediction never came true — neil_chilson · 2026-09-26
- Halcyon's founder: AI safety lacks founders, not capital — The Cognitive Revolution · 2026-09-26
- Halcyon CEO: AI safety's bottleneck is founders, not capital — it has seeded ~30 new orgs — The Cognitive Revolution · 2026-09-26