Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Avast Antivirus Vulnerability Exposed by Chaotic Eclipse

Avast Antivirus Vulnerability Exposed by Chaotic Eclipse

Posted on September 3, 2026 By CWS

Cybersecurity researcher Chaotic Eclipse has uncovered a serious zero-day vulnerability in Avast Antivirus, which has been publicly disclosed through a proof-of-concept repository named PrettyPrague. This vulnerability, found in Avast’s Sandbox component, threatens to escalate user privileges on fully updated Windows 11 systems, raising significant security concerns.

Details of the Security Flaw

The researcher, known on GitHub as MSNightmare, claims the vulnerability can be exploited on patched versions of Avast Antivirus. The flaw is an elevation-of-privilege issue within the Avast Sandbox, which is designed to provide a secure environment for isolating suspicious files. By manipulating this sandbox mechanism, attackers could potentially access the Windows Security Account Manager (SAM) database and gain NT AUTHORITYSYSTEM privileges.

The SYSTEM authority grants significant control over a system, allowing attackers to bypass standard user account restrictions. This could enable unauthorized access to protected credentials, the disabling of security features, and the installation of persistent malware or alteration of critical system settings.

Extent and Impact of the Vulnerability

The public repository indicates that the proof of concept is compatible with all versions of Avast Antivirus, although this has not been independently corroborated by a vendor advisory or a public CVE reference. The author speculates that other GenDigital products, such as AVG and Norton, might also be affected, but no technical confirmation has been provided for these claims.

The repository, last updated on August 30, 2026, includes C and C++ project files and outlines exploiting the Avast Sandbox flaw to access the SAM database and initiate a SYSTEM shell. The public availability of this repository increases the risk of exploitation by both researchers and potential attackers.

Recommendations for Organizations

Organizations using Avast Antivirus should remain vigilant and monitor any official security advisories from GenDigital. It’s crucial to verify installed product versions and configurations while reviewing endpoint telemetry for unusual processes related to Avast services or sandbox components.

Security teams should be alert for unexpected SAM database access, unusual registry activities, and new SYSTEM-level processes. Detection rules should focus on suspicious execution chains involving low-privileged user processes interacting with antivirus sandbox services.

Currently, no CVE number or coordinated vendor response has been announced, nor is there evidence of a patch. Until further details are confirmed, this vulnerability should be treated as an unverified but potentially serious threat.

Cyber Security News Tags:Avast Antivirus, AVG, Chaotic Eclipse, Cybersecurity, GenDigital, Norton, privilege escalation, SAM database, sandbox mechanism, security advisory, Windows 11, zero-day vulnerability

Post navigation

Previous Post: ScreenConnect Exploited to Distribute Malware on Windows
Next Post: Claude AI Outage Disrupts Key Models and Services

Related Posts

Threat Actor Allegedly Claim Leak of NordVPN Salesforce Database with Source Codes Threat Actor Allegedly Claim Leak of NordVPN Salesforce Database with Source Codes Cyber Security News
Chrome 140 Released With Fix For Six Vulnerabilities that Enable Remote Code Execution Attacks Chrome 140 Released With Fix For Six Vulnerabilities that Enable Remote Code Execution Attacks Cyber Security News
Apache Struts 2 DoS Vulnerability Let Attackers Crash Server Apache Struts 2 DoS Vulnerability Let Attackers Crash Server Cyber Security News
VoidLink Rootkit Exploits Linux with Advanced Techniques VoidLink Rootkit Exploits Linux with Advanced Techniques Cyber Security News
AI Pentest Tool Enhances Security Testing with New Features AI Pentest Tool Enhances Security Testing with New Features Cyber Security News
Microsoft PlayReady DRM Used by Netflix, Amazon, and Disney+ Leaked Online Microsoft PlayReady DRM Used by Netflix, Amazon, and Disney+ Leaked Online Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Affordable SweepLED Device Detects Hidden Cameras in Hotels
  • FBI Investigates Massive Driver’s License Leak on Dark Web
  • Hackers Exploit QR Codes in Phishing Scams
  • Claude AI Outage Disrupts Key Models and Services
  • Avast Antivirus Vulnerability Exposed by Chaotic Eclipse

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Affordable SweepLED Device Detects Hidden Cameras in Hotels
  • FBI Investigates Massive Driver’s License Leak on Dark Web
  • Hackers Exploit QR Codes in Phishing Scams
  • Claude AI Outage Disrupts Key Models and Services
  • Avast Antivirus Vulnerability Exposed by Chaotic Eclipse

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark