AirKeyboard iOS App 1.0.5 – Remote Input Injection

# Exploit Title: AirKeyboard iOS App 1.0.5 – Remote Input Injection # Date: 2025-06-13 # Exploit Author: Chokri Hammedi # Vendor Homepage: https://airkeyboardapp.com # Software Link: https://apps.apple.com/us/app/air-keyboard/id6463187929 # Version: Version 1.0.5 # Tested on: iOS 18.5 with AirKeyboard app ”’ Description: The AirKeyboard iOS application exposes a WebSocket server on port 8888 which…

Read More

How to swerve Donald Trump’s tariffs

“Nobody is getting off the hook for unfair trade balances,” insists Donald Trump. The exemptions and exclusions to the tariffs he has imposed on imports to America would suggest otherwise. His “reciprocal” tariffs announced on April 2nd included a 37-page annexe with exemptions for $644bn-worth of American imports, about a fifth of the total. On…

Read More

Microsoft Excel Use After Free – Local Code Execution

# Titles: Microsoft Excel Use After Free – Local Code Execution # Author: nu11secur1ty # Date: 06/09/2025 # Vendor: Microsoft # Software: https://www.microsoft.com/en/microsoft-365/excel?market=af # Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-27751 # Versions: MS Excel 2016, MS Office Online Server KB5002699 # CVE-2025-27751 ## Description: The attacker can trick any user into opening and executing their code by sending…

Read More