Kernel Exploitation
-
CatchPulse Antivirus Zero-Days: From File Leaks to LPE (A Look at CVE-2026-11459 and CVE-2026-15506)
What happens when your antivirus becomes the easiest way to compromise your system? In this post, I uncover two zero-day vulnerabilities in the CatchPulse driver that allow an attacker to bypass weak process “authentication,” abuse privileged file operations to dump sensitive data like password hashes, and ultimately trigger a kernel heap overflow for arbitrary read/write…
