ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)
Vercel patched two critical Next.js vulnerabilities allowing unauthenticated remote code execution. The AVIF flaw (GHSA-2xp9-vwfh-vxw4, CVSS 9.5) stems from a libheif heap buffer overflow; the Windows path traversal (CVE-2026-75604, CVSS 9.0) affects Pages and App Router. Fixes ship in Next.js 15.5.24 and 16.3.3.
Tracked by ByteBrief