- My current research interest is focused on vulnerability research with LLM. I have previously worked as a vulnerability researcher at SSD Labs, PK Security, and {CONFIDENTIAL}, and my main focus was on Browser and Mobile (Android/iOS)
- Security Researcher @ {CONFIDENTIAL} (2023.02 ~ 2023.09)
- Security Researcher @ PK Security (2023.07 ~ 2023.09)
- Security Researcher @ SSD Labs (2022.05 ~ 2023.06)
- Intended Ph.D. Student @ Korea University - USELab (???)
- B.S. Student @ Korea University Sejong - A.I. Cyber Security (2021.03 ~ Now)
- KITRI "BEST OF THE BEST" 9th Vulnerability Analysis - (2020.07.01 ~ 2021.03.26)
- Member. Virtualization Software Bug Hunting {Team. VirtualBoBs} [BOB 9th]
- Project Leader. Unreal Engine Bug Hunting {Team. GameCrashProject(GCP)} [BOB 10th]
- Project Leader. Apple Safari Bug Hunting {Team. ApplePIE} [BOB 11th]
- Project Leader. CMS Fuzzing {Team. What The Fuzz} [BOB 12th]
- Project Leader. V8 1-Day Analysis [White Hat School 1st]
- Project Leader. Office Application Vulnerability Analysis {Team. bObffice} [BOB 13th]
- LG Electronics Vulnerability Report Letter of Appreciation
- Microsoft MSRC 2022 Q1 TOP 100 Security Researcher
- Mozilla 2022 Q1 Firefox Bug Bounty Rewards Hall of Fame
- Apple Web Service Security Acknowledgements Hall of Fame -November. 2022 (Donated, $10,000)
- Mozilla 2023 Q2 Firefox Bug Bounty Rewards Hall of Fame
- Mozilla 2023 Q3 Firefox Bug Bounty Rewards Hall of Fame
- Apple Web Service Security Acknowledgements Hall of Fame - January. 2024
- Apple Web Service Security Acknowledgements Hall of Fame - June. 2024
- Mozilla 2024 Q1 Firefox Bug Bounty Rewards Hall of Fame
- Mozilla 2024 Q3 Firefox Bug Bounty Rewards Hall of Fame
- 2022 BOB Information Security Open Conference (BISC) - Browser Security
- 2023 National Security Research Institute (국가보안기술연구소) - {CONFIDENTIAL}
- 2023 BOB Information Security Open Conference (BISC) - Offensive Field Experience for 1 year
List of Browser
- CVE-2022-1638 : Heap-Buffer-Overflow in Google Chrome
- CVE-2022-32787 : Out-Of-Bounds Write in Apple Safari
- CVE-2022-32816 : UI Spoofing in Apple Safari
- Chrome BETA, Issue 1335688 : Heap-Buffer-Overflow in Google Chrome
- CVE-2022-42799 : UI Spoofing in Apple Safari
- CVE-2022-42823 : Type Confusion in Apple Safari
- CVE-2022-42824 : Same-Origin Policy Bypass in Apple Safari
- CVE-2022-46698 : Same-Origin Policy Bypass in Apple Safari
- CVE-2022-46875 : Download Protections Bypass in Mozilla Firefox
- CVE-2023-23517 : Type Confusion in Apple Safari [ApplePIE]
- CVE-2023-23518 : Type Confusion in Apple Safari [ApplePIE]
- CVE-2023-25741 : Same-Origin Policy Bypass in Mozilla Firefox
- CVE-2023-29531 : Out-Of-Bounds Access in Mozilla Firefox
- CVE-2023-28201 : Use-After-Free in Apple Safari
- Issue 1343317 : Insufficient policy enforcement in Google Chrome
- CVE-2023-4582 : Buffer Overflow in Mozilla Firefox
- CVE-2023-39434 : Use-After-Free in Apple Safari
- CVE-2023-40403 : ASLR Bypass in Apple Safari
- ZDI-23-1583 : Double-Free in Google Chrome
- CVE-2023-6856 : Heap-Buffer-Overflow Sandbox Escape in Mozilla Firefox
- CVE-2024-6600 : Out-Of-Bounds Access in Mozilla Firefox
- CVE-2024-8383 : Improper Input Validation in Mozilla Firefox
- CVE-2024-11691 : Out-Of-Bounds Write Sandbox Escape in Firefox
List of Mobile
- CVE-2024-23286 : Heap Buffer Overflow in Apple CoreGraphics
- SVE-2024-0092(CVE-2024-20861) : Use-After-Free in Samsung Galaxy SveService
- SVE-2024-0096(CVE-2024-20862) : Out-Of-Bounds Write in Samsung Galaxy SveService
- [Severity Low, Bounty Awarded] : Improper input validation in frcmc-service
- CVE-2024-23282 : Improper Input Validation lead to initiate FaceTime calls without user authorization in Apple iOS Mail
List of Virtualization
- CVE-2021-2086, CVE-2021-35540 : Denial of Service in Oracle VirtualBox
- CVE-2022-39421 : Remote Code Execution in Oracle VirtualBox
List of Office Software
- CVE-2021-34280 : Uninitialized Pointer in Polaris Office
- CVE-2021-34973, CVE-2022-37378 : Use-After-Free in Foxit PDF Reader
- CVE-2021-45978, CVE-2021-45979, CVE-2021-45980, CVE-2021-42678, CVE-2021-42679 : Command Injection in Foxit PDF Reader
- CVE-2022-24370, CVE-2022-24356, ZDI-CAN-15299, CVE-2022-37376 : Out-Of-Bounds Read in Foxit PDF Reader
- CVE-2022-24954 : Stack-Based Buffer Overflow in Foxit PDF Reader
- CVE-2022-24955 : Improper Access Control in Foxit PDF Reader
- CVE-2022-30557, CVE-2022-37377 : Type Confusion in Foxit PDF Reader
- CVE-2022-22004 : Improper Access Control in Microsoft Office
- CVE-2022-23202 : Improper Access Control in Adobe Product
List of Anti-Virus
- CVE-2022-0129 : Improper Access Control in McAfee Product
- CVE-2022-26319, CVE-2022-26337 : Improper Access Control in Trend Micro Product
- CVE-2023-25143 : RCE in Trend Micro Apex One
List of VPN
- CVE-2022-0517 : Improper Access Control in Mozilla VPN
List of Drivers
- SVE-2022-0082 (CVE-2022-27842), SVE-2022-0083 (CVE-2022-27843), SVE-2022-0115 (CVE-2022-28541), SVE-2021-24333 (CVE-2022-28779), SVE-2022-0854 (CVE-2022-30744), SVE-2022-1099 (CVE-2022-33711), SVE-2022-0855(CVE-2022-36840), SVE-2022-1770(CVE-2022-39845) : Improper Access Control in Samsung Driver
- CVE-2022-24543 : Improper Access Control in Microsoft Windows Upgrade Assistant