Signal Bing Images RCEs: How XBOW Found Three Critical Flaws
Summary
XBOW disclosed the exploit mechanism for three Bing Images vulnerabilities on 23 July 2026, after Microsoft requested that publication wait until patching was complete. The three flaws, CVE-2026-32194, CVE-2026-32191 and CVE-2026-21536, all carry a CVSS score of 9.8 and require no authentication, cookies or user interaction. A crafted SVG achieved command execution as NT AUTHORITY\SYSTEM on Microsoft's production image processing workers, and as root on the same team's Linux machines. The proof of concept ran to three lines, using an xlink:href attribute beginning with a pipe character to exploit a conversion layer where ImageMagick delegate functionality remained enabled. This repeats the failure class of ImageTragick, CVE-2016-3714, from 2016. XBOW was credited as the finder of all three in Microsoft's acknowledgement list and entered the top ten of the bug bounty leaderboard, the first and only AI to reach that ranking.
Classification
Evidence 1
- XBOW (자율 공격형 보안 스타트업) 기술 블로그 2026-07-23 accessed 2026-07-28T13:59:42+00:00
Part of trends 0
No objects.
Directly linked issues 0
No objects.
Public id: fm-cdea7fca95e9