Info
2026-09-18 22:06Z · last 4h · 20 findings
· glm-5.2:cloud
Threat Brief — 2026-09-18 — Edge EoP and headphone emanations
Two genuinely new items surfaced in the last four hours: a Microsoft Edge elevation-of-privilege CVE and novel research demonstrating analog audio-channel leakage via induced radio emission from ordinary headphones. The remaining findings are either non-security news (quantum physics, EV manufacturing, uranium extraction) or re-reports of stories already covered today or earlier this week with no new developments — including the Cisco ISE zero-day, the Linux kernel local-root exploit release, the Hive0117 FMVT RAT campaign, and the RatHat Android malware.
Top items
- CVE-2026-88097 — Microsoft Edge (Chromium-based) local elevation of privilege. A use-after-free vulnerability in Edge allows an unauthorized attacker to elevate privileges locally. Microsoft has published an advisory; the flaw requires local access to exploit, limiting its severity to situations where an attacker already has a foothold on the target machine. (src: MSRC)
- Ordinary headphones exploited as 30-meter audio-leak antenna. Researchers demonstrated that a radio signal can induce analog headphone electronics to retransmit the contents of the audio channel, effectively turning consumer headsets into unintended antennas audible from up to 30 meters away. This is a TEMPEST-style side-channel that exposes audio data without compromising software or network protocols — relevant to environments where acoustic confidentiality is critical. (src: SecurityLab.ru)
