discovered 03 Aug 2026
CVE-2025-32463
→ View on GitHubCVE-2025-32463 is a Go-based exploit tool designed to exploit a critical local privilege escalation vulnerability in sudo versions 1.9.14 to 1.9.17. The tool manipulates the `--chroot` option to load a malicious shared library, allowing unauthorized users to gain root access. Notable features include the ability to run the exploit in both normal and silent modes, and it supports building from source or using a pre-built binary.