Vulnerability research · Riyadh
Five CVEs. Every one fixed before you read this.
Two independent researchers in Riyadh. We break browsers and the software the world runs on, then hand the vendor the root cause and the patch.
Vendors who shipped our fixes · where we compete
How we work
Two independent researchers. We are not a consultancy and we do not take engagements — we pick our own targets, work them until they break, and publish everything once the vendor has shipped a fix.
How we work
We pick the target
Software the world actually runs — browsers, messaging platforms, the libraries underneath them. We write down why a target is worth the time before we touch it, and we drop it when the thesis stops holding.
We find the root cause
Not “it crashes” — why it crashes. Use-after-free, uninitialised heap disclosure, process-isolation bypasses, stored XSS. The class of bug that survives a code review because it only shows up at runtime.
We disclose it properly
Private report first, always. A minimised reproducer and an analysis written for the engineer who has to land the patch. Nothing gets published until the fix has shipped and users have had time to take it.
Where the bugs came from
Browser internals
Four CVEs in Mozilla Firefox across ImageLib, Text, WebRender and Form Autofill — including a content-process use-after-free rated CVSS 9.8 and reachable from an ordinary web page.
Application security
Stored XSS in CometChat group messages: a payload that persists server-side and executes for every member who opens the conversation. Reported privately, fixed by the vendor.
Competition
First blood on the reverse engineering track at the Tuwaiq Cyber Challenge, third at Black Hat MEA 2025, first at Tuwaiq Mobile CTF. Live competition is the closest thing to a real clock.
None of this is a claim you have to take on trust. Read the research →
$ cat cves.txt
The work, as the vendors recorded it
Use-after-free in RasterImage surface discard
Firefox stores decoded image surfaces in a SurfaceCache keyed by a raw, non-owning pointer to the owning image, and notifies that…
Uninitialized heap disclosure through a crafted web font
Firefox sanitizes web fonts through OTS before use.
Stored XSS in CometChat group messages
An authenticated user can inject a persistent JavaScript payload into a group chat message through the data.text parameter of the…
Fission site-isolation bypass via missing PipelineId namespace check
Under Fission each content process owns a PipelineId namespace.
Reach
Five bugs found in Riyadh. Patched on every continent.
Every vulnerability below was reported privately from here, fixed by the vendor, and shipped in a release that reached the whole install base. The scores and statuses below are pulled live from NIST’s National Vulnerability Database every time this page loads — our disclosure record, read straight from the source. Not telemetry, and not a threat feed.
The crew
Two people, two halves of the same problem
Abdulaziz Alasaiqah
Vulnerability research · web & browser security
Five published CVEs across Mozilla Firefox and CometChat — a content-process use-after-free in ImageLib, an uninitialised heap leak through a crafted web font, a WebRender Fission bypass, test-only autofill handlers shipped to production, and a stored XSS in group messaging. eCPPTv3, eJPTv2. 1,060+ points on BugBounty.sa.
LinkedIn →Ahmed Albalawi
Red team · adversary simulation
Red team operator and CTF player. Focused on offensive security and adversary simulation — not just finding vulnerabilities, but understanding why they exist and how an attacker actually reaches them. Windows internals, malware tradecraft, and full-chain operations. CRTO, OSCP+, OSCP, eCDFP, CCNA.
LinkedIn →Third-party record
Don’t take our word for it.
Mozilla · Firefox security team
4 CVEs
Credited across ImageLib, Text, WebRender and Form Autofill — including a CVSS 9.8 use-after-free reachable from an ordinary web page. Bounty awarded.
BugBounty.sa · Saudi national platform
1,060+
Points on the national bug bounty platform, plus third place in the BugBounty Joiner competition.
Black Hat MEA 2025 · Bug bounty junior
3rd
Third against the region’s bug bounty field, at the largest security event in the Middle East.
Tuwaiq Academy · Mobile CTF
1st
First across the line in a national mobile application exploitation competition.
Tuwaiq Cyber Challenge · Reverse engineering
3rd
Third overall, and first blood on the reverse engineering track — first competitor to solve it.
Defensathon · Project SATE’
2nd
Second place for an AI-guided counter-UAS laser defence system — detection, tracking and low-cost interception.
CometChat · messaging platform
Stored XSS in group messages, reported privately and fixed by the vendor before anything was published here. CVE-2026-39154
Certifications · both operators
CRTO · OSCP+ · OSCP · eCDFP · CCNA · eCPPTv3 · eJPTv2. Earned, not collected.
Get in touch
Questions about the research, something to report, or an invitation to speak.