security issues

Winsage
November 20, 2025
Qualcomm has decoupled GPU updates from Microsoft's OS release cycle, allowing Snapdragon X Elite owners to download graphics drivers directly, which aligns the company with industry standards set by Nvidia and AMD. The company has transitioned to a direct "Upgradable Graphics Drivers" (UGD) model, enabling immediate access to driver updates through Qualcomm’s portal. The beta "Adreno Control Panel" has been rebranded to the "Snapdragon Control Panel," which now includes game-specific profiling and optimization features. Qualcomm has also integrated support for AVX and AVX2 instruction sets, addressing compatibility issues with games like God of War and Control. Kernel-level anti-cheat support has been introduced, making multiplayer gaming more accessible on Arm-based systems. The Snapdragon X2 Elite is set to launch in the first half of 2026, promising "Day 0" driver support and the ability to run 90% of top games, with performance expectations to outperform Intel’s Lunar Lake architecture.
Winsage
November 16, 2025
Microsoft is facing significant user dissatisfaction with Windows 11 due to core functionality issues, particularly following the KB5066835 update that compromised the Windows Recovery Environment. This update caused mouse and keyboard operations to fail for many users, coinciding with the discontinuation of free security updates for Windows 10. Users are frustrated with the introduction of AI features, such as the Recall AI, which raises privacy concerns and cannot be fully removed. Feedback indicates a desire for a more reliable operating system, akin to Windows 10, without disruptive AI elements. Recent updates have also introduced regressions affecting developers and peripheral functionality, leading to doubts about Microsoft's prioritization of user needs. Historically, Microsoft has responded to user backlash by making adjustments, but the current situation highlights a disconnect between the company's AI ambitions and user expectations for stability and reliability.
Winsage
November 13, 2025
Microsoft's Windows chief, Pavan Davuluri, introduced the concept of an "agentic" operating system, which aims to integrate applications, cloud services, and devices for a more autonomous user experience. This vision has generated skepticism among users, who fear it may lead to intrusive AI interactions. The term "agentic" refers to systems capable of performing multi-step tasks on behalf of users, potentially enhancing integration with file systems, notifications, and cloud services. However, past experiences with intrusive advertisements and privacy concerns have led to a trust deficit among users. The introduction of such systems raises privacy and security issues, prompting regulatory scrutiny and calls for explicit permissions, human confirmation for significant actions, and robust local processing. Hardware manufacturers are investing in AI PCs to support these developments, while developers will have access to new APIs for application integration. Microsoft faces a messaging challenge in promoting this vision, needing to demonstrate clear benefits and prioritize user agency to alleviate concerns.
Winsage
October 17, 2025
Check Point Research (CPR) identified a significant security vulnerability in the Rust-based kernel component of the Graphics Device Interface (GDI) in Windows, reported to Microsoft in January 2025. The issue was resolved in OS Build 26100.4202, part of the KB5058499 update released on May 28, 2025. The vulnerability was discovered during a fuzzing campaign targeting the Windows graphics component through metafiles, revealing multiple security issues including information disclosure and arbitrary code execution. The specific bug was linked to a crash occurring during the execution of a NtGdiSelectClipPath syscall in the win32kbasers.sys driver, triggered by an out-of-bounds memory access when processing malformed metafile records. Microsoft classified the vulnerability as moderate severity and addressed it in a non-security update, implementing substantial changes to the affected kernel module.
AppWizard
October 15, 2025
Security researchers have identified a data theft technique called Pixnapping that exploits vulnerabilities in Android devices, specifically targeting sensitive information from various applications without needing special permissions. This method allows malicious apps to capture data from other apps or websites, including sensitive information from platforms like Google Maps, Gmail, Signal, Venmo, and two-factor authentication codes from Google Authenticator. The technique utilizes a hardware side channel known as GPU.zip to read screen pixel data by measuring rendering times. The data leak rate is between 0.6 to 2.1 pixels per second, sufficient to reconstruct sensitive information. The vulnerability is designated as CVE-2025-48561 and affects Android versions 13 through 16, including devices like the Pixel 6 to 9 and Galaxy S25. A partial patch was released in September 2025, with a comprehensive solution expected in December. The attack allows benign applications from the Google Play Store to potentially spy on sensitive on-screen data, highlighting broader concerns regarding side-channel vulnerabilities that arise from hardware data processing rather than software bugs. While Google has stated there is no evidence of exploitation currently, the existence of this attack suggests that malware could bypass traditional security measures. Google is working on additional fixes to limit misuse of the blur API and improve detection capabilities, but the underlying GPU.zip vulnerability remains unresolved. Users are advised to avoid untrusted apps and keep their devices updated, as more side-channel attacks similar to Pixnapping may emerge in the future.
Search