Entering and Breaking the Avast Antivirus Sandbox Part 2
safateam
110 points
30 comments
September 25, 2026
Related Discussions
Found 5 related stories in 82.4ms across 7,702 title embeddings via pgvector HNSW
- Sandbox Escape Vulnerabilities Across 4 Coding Agent Vendors fogeltine · 11 pts · July 20, 2026 · 59% similar
- Software sandboxing: The basics (2025) mococa · 82 pts · September 20, 2026 · 55% similar
- CVE-2026-25089: FortiSandbox unauthenticated command injection added to CISA KEV slvnx · 31 pts · July 16, 2026 · 53% similar
- Actively exploited sandbox RCE in all Chromium versions negura · 396 pts · September 04, 2026 · 52% similar
- Chrome's Breaking and Entering ingve · 25 pts · July 24, 2026 · 50% similar
Discussion Highlights (3 comments)
x-complexity
Chalk another one up for "Antiviruses causing more problems than solving them". They 'worked' when they initially just scanned files for known malicious signatures. Now they're the equivalent of a sledgehammer to a wall with all of the extra bells & whistles strapped to them. Application whitelisting is the remaining way forward if you actually care about runtime security. That & locking every access point down to the bare minimum.
wzdd
That's an impressively tight TOCTOU exploit!
fathermarz
I have lost faith in signature AV and CVE feeds for that matter. Attackers test against scanners until they come back clean and avoid known fingerprints. The only way I see to catch things now is behaviour diffing through static analysis. Disclosure: I build Vigilance, which does this.