Out-of-bounds read in bitmap serialization
Integer underflow in bitmap serialization -> OOB read. Structure-aware LibFuzzer harnesses at 90%+ code coverage. Coordinated disclosure.
I break software and figure out why it broke: writing fuzzers, triaging crashes, building exploits. Mostly userland memory corruption, kernel stuff, and mobile targets right now.
I co-lead the RITSEC Vulnerability Research Interest Group, where I mentor ~7 students on modern mitigations (PAC, MTE) and how to beat them. We're currently trying to fuzz XNU, which is going about as well as you'd expect.
BS Cybersecurity at RIT. Class of 2027. Glen Burnie, MD.
70 72 6f 62 65 2e 20 62 72 65 61 6b 2e 20 70 72 |probe. break. pr| 6f 76 65 2e 0a 00 00 00 00 00 00 00 00 00 00 00 |ove..............|
Integer underflow in bitmap serialization -> OOB read. Structure-aware LibFuzzer harnesses at 90%+ code coverage. Coordinated disclosure.
Both RCE-class. Resource-constrained coverage-guided fuzzing. 90-day coordinated disclosure.
Heap over-reads and UAF writes. Custom syzkaller definitions + agentic source analysis.
Three published writeups + fully reliable PoC chains: CVE-2023-4068 (WASM/JS null type confusion), CVE-2025-5419 (ITW StoreStoreElimination), CVE-2025-5959 (Wasm type canonicalization + MurmurHash64A birthday attack). Type confusion -> sandbox escape -> code exec. Reversed TurboFan/Maglev pipelines, GC behavior, JSPI stack switching.
10+ node distributed fuzzer, PostgreSQL-backed corpus sync. Thompson Sampling for mutator selection: ~35% faster coverage growth vs static weights. Coverage plateau detection with ML-based corpus generation. Turned up undocumented V8 JIT optimization flaws.
Automated RE pipeline on headless Ghidra with LLaMA-based function signature recovery. Ran it on 4 ICS firmware images (Cisco IOS, Digi Transport, Phoenix Contact), cut manual analysis 70%.
eBPF-based process hiding via bpf_probe_read hook interception and syscall table manipulation. Built to study stealth/persistence techniques and inform defensive detection.
Designed 5 challenges across 4 categories. Grounded in current papers (ePrint 2025/376, Tree Borrows PLDI 2025, Bourefis et al. MobiSec 2024): chained CSIDH-512 oracle attacks, Kipnis-Shamir UOV key recovery, Intel TSX anti-debugging RE, SDR/FHSS protocol RE, deterministic Rust+C CFI bypass.
Details TBD ;)
Also secret.
Expect custom challenges :3