<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Numb3rs' blog</title><link>https://numb3rs.re/</link><description>Recent content on Numb3rs' blog</description><generator>Hugo</generator><language>en</language><lastBuildDate>Mon, 05 Oct 2026 14:12:09 -0700</lastBuildDate><atom:link href="https://numb3rs.re/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-23866: Finding a Whatsapp NDay</title><link>https://numb3rs.re/posts/cve-2026-23866-finding-a-whatsapp-nday/</link><pubDate>Mon, 05 Oct 2026 14:12:09 -0700</pubDate><guid>https://numb3rs.re/posts/cve-2026-23866-finding-a-whatsapp-nday/</guid><description>On May 1 2026, CVE-2026-23866 was published, the vulnerability reportedly allows a malicious attacker to force a victim into loading an arbitrary URL and thus leaking important information (headers, ip address, &amp;hellip;). It&amp;rsquo;s a low grade vulnerability but I&amp;rsquo;ve never worked on Whatsapp so I figured it&amp;rsquo;d be interesting to take a look at it.
The only informations I will be using are those publicly available on the NIST website .</description></item><item><title>About</title><link>https://numb3rs.re/about/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://numb3rs.re/about/</guid><description>About me. My name is Côme, I&amp;rsquo;m a 19 year old French student at Arizona State University, studying Computer Science and Philosophy.
I played with different CTF teams as a pwner:
ECSC Team France (Junior member in 2023 and 2024) World Wide Flag Shellphish (sometimes) Been working for 2 years on mobile security as a freelancer. I&amp;rsquo;m very interested in iOS security.
CVEs N.B: I have no time to make such work public anymore, hence why I don&amp;rsquo;t have any recent one.</description></item></channel></rss>