IBM AIX's Unix domain datagram socket implementation could potentially expose applications using Unix domain datagram sockets with SO_PEERID operation and may lead to privilege escalation. CVSS Base score: 8.1
The research paper has shown the existence of a vulnerability in the German eID scheme, posing a significant risk to all services relying on the eID, especially those handling sensitive data such as insurances, banks, and government services.
The vulnerability has the CVE-ID CVE-2024–23674 and a CVSS rating of 9.7 (Critical)
A bank account has been successfully opened in the name of a victim at a major German bank.
Without the next element of the "Look-and-say sequence", 312211, for the example in the title there can also be rules that yield 111111211, or one of: (221211, 111211, 121211, 211211)
But what can one do now? It's no longer inaccurate :-)