<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Firezone Security Advisories</title>
    <link>https://www.firezone.dev/security-advisories</link>
    <description>Security vulnerabilities disclosed in Firezone, with affected components, vulnerable and fixed versions, impact, and remediation guidance.</description>
    <language>en-us</language>
    <atom:link href="https://www.firezone.dev/security-advisories/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>FZ-2026-006: Windows device ID file is world-readable, allowing device verification bypass</title>
      <link>https://www.firezone.dev/security-advisories/fz-2026-006</link>
      <guid isPermaLink="true">https://www.firezone.dev/security-advisories/fz-2026-006</guid>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[On Windows Clients prior to 1.5.13, the device ID file was readable by any local user, so its contents could be copied to another machine to bypass device verification policies.]]></description>
    </item>
    <item>
      <title>FZ-2026-005: Windows GUI Client reads configuration from user-writable locations</title>
      <link>https://www.firezone.dev/security-advisories/fz-2026-005</link>
      <guid isPermaLink="true">https://www.firezone.dev/security-advisories/fz-2026-005</guid>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Windows GUI Clients prior to 1.5.13 stored their advanced settings in a user-writable directory and read MDM policy from the per-user registry hive, letting any same-user process change how the privileged tunnel connects.]]></description>
    </item>
    <item>
      <title>FZ-2026-004: Linux GUI Client stores its configuration in a user-writable location</title>
      <link>https://www.firezone.dev/security-advisories/fz-2026-004</link>
      <guid isPermaLink="true">https://www.firezone.dev/security-advisories/fz-2026-004</guid>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Linux GUI Clients prior to 1.5.13 stored their advanced settings in a directory under the user's home that any same-user process could modify, influencing how the privileged tunnel connects.]]></description>
    </item>
    <item>
      <title>FZ-2026-003: Windows GUI Client named pipes accept connections from other local processes</title>
      <link>https://www.firezone.dev/security-advisories/fz-2026-003</link>
      <guid isPermaLink="true">https://www.firezone.dev/security-advisories/fz-2026-003</guid>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Windows GUI Clients prior to 1.5.13 created their tunnel and GUI named pipes without package-scoped access control, letting other local processes drive the privileged tunnel service, change settings, or hijack deep-link handoff.]]></description>
    </item>
    <item>
      <title>FZ-2026-002: Linux tunnel service IPC socket accepts connections from any same-user process</title>
      <link>https://www.firezone.dev/security-advisories/fz-2026-002</link>
      <guid isPermaLink="true">https://www.firezone.dev/security-advisories/fz-2026-002</guid>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Linux GUI Clients prior to 1.5.13 authorized peers on the tunnel service IPC socket only by group membership, letting any process running as the desktop user drive the privileged tunnel and change Client settings.]]></description>
    </item>
    <item>
      <title>FZ-2026-001: macOS Client lets local processes modify its configuration</title>
      <link>https://www.firezone.dev/security-advisories/fz-2026-001</link>
      <guid isPermaLink="true">https://www.firezone.dev/security-advisories/fz-2026-001</guid>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[macOS Clients from 1.4.15 through 1.5.15 stored their configuration in a UserDefaults domain writable by any unprivileged local process, allowing the Client's settings to be tampered with. Clients with configuration forced via MDM are not affected.]]></description>
    </item>
  </channel>
</rss>
