PHP Object Injection: unserialize() and the Magic-Method Chain
Calling unserialize() on attacker-controlled input instantiates arbitrary classes and fires their magic methods automatically. Here is how a POP gadget chain rides __wakeup and __destruct to a dangerous sink, and why json_decode is the fix.