Researcher Chaotic Eclipse has claimed to have discovered a zero-day privilege-escalation vulnerability affecting Avast Antivirus and released a public proof-of-concept repository named PrettyPrague.
The researcher behind the project, using the GitHub handle MSNightmare, says the issue can be exploited on fully patched Avast Antivirus installations running fully updated Windows 11 25H2 systems.
The alleged flaw is described as an elevation-of-privilege vulnerability in Avast Sandbox, a component designed to isolate suspicious files and reduce the damage from potentially malicious programs.

