Vulnerability research · Riyadh

Five CVEs. Every one fixed before you read this.

Two independent researchers in Riyadh. We break browsers and the software the world runs on, then hand the vendor the root cause and the patch.

Vendors who shipped our fixes · where we compete

Mozilla Mozilla Firefox CometChat Tuwaiq Academy BugBounty.sa INE Mozilla Mozilla Firefox CometChat Tuwaiq Academy BugBounty.sa INE
Mozilla Mozilla Firefox CometChat Tuwaiq Academy BugBounty.sa INE Mozilla Mozilla Firefox CometChat Tuwaiq Academy BugBounty.sa INE

How we work

Two independent researchers. We are not a consultancy and we do not take engagements — we pick our own targets, work them until they break, and publish everything once the vendor has shipped a fix.

How we work

We pick the target

Software the world actually runs — browsers, messaging platforms, the libraries underneath them. We write down why a target is worth the time before we touch it, and we drop it when the thesis stops holding.

We find the root cause

Not “it crashes” — why it crashes. Use-after-free, uninitialised heap disclosure, process-isolation bypasses, stored XSS. The class of bug that survives a code review because it only shows up at runtime.

We disclose it properly

Private report first, always. A minimised reproducer and an analysis written for the engineer who has to land the patch. Nothing gets published until the fix has shipped and users have had time to take it.

Where the bugs came from

Browser internals

Four CVEs in Mozilla Firefox across ImageLib, Text, WebRender and Form Autofill — including a content-process use-after-free rated CVSS 9.8 and reachable from an ordinary web page.

Application security

Stored XSS in CometChat group messages: a payload that persists server-side and executes for every member who opens the conversation. Reported privately, fixed by the vendor.

Competition

First blood on the reverse engineering track at the Tuwaiq Cyber Challenge, third at Black Hat MEA 2025, first at Tuwaiq Mobile CTF. Live competition is the closest thing to a real clock.

None of this is a claim you have to take on trust. Read the research →

Reach

Five bugs found in Riyadh. Patched on every continent.

Every vulnerability below was reported privately from here, fixed by the vendor, and shipped in a release that reached the whole install base. The scores and statuses below are pulled live from NIST’s National Vulnerability Database every time this page loads — our disclosure record, read straight from the source. Not telemetry, and not a threat feed.

National Vulnerability Database syncing…
CVE-2026-74943 9.8 CRITICAL Modified · published 2026-08-18
Use-after-free in RasterImage surface discard · Mozilla Firefox
Reported from Riyadh Carried by the vendor release 384,715 CVEs in NVD — five are ours

The crew

Two people, two halves of the same problem

AA

Abdulaziz Alasaiqah

Vulnerability research · web & browser security

Five published CVEs across Mozilla Firefox and CometChat — a content-process use-after-free in ImageLib, an uninitialised heap leak through a crafted web font, a WebRender Fission bypass, test-only autofill handlers shipped to production, and a stored XSS in group messaging. eCPPTv3, eJPTv2. 1,060+ points on BugBounty.sa.

LinkedIn →
AB

Ahmed Albalawi

Red team · adversary simulation

Red team operator and CTF player. Focused on offensive security and adversary simulation — not just finding vulnerabilities, but understanding why they exist and how an attacker actually reaches them. Windows internals, malware tradecraft, and full-chain operations. CRTO, OSCP+, OSCP, eCDFP, CCNA.

LinkedIn →

Third-party record

Don’t take our word for it.

Mozilla · Firefox security team

4 CVEs

Credited across ImageLib, Text, WebRender and Form Autofill — including a CVSS 9.8 use-after-free reachable from an ordinary web page. Bounty awarded.

BugBounty.sa · Saudi national platform

1,060+

Points on the national bug bounty platform, plus third place in the BugBounty Joiner competition.

Black Hat MEA 2025 · Bug bounty junior

3rd

Third against the region’s bug bounty field, at the largest security event in the Middle East.

Tuwaiq Academy · Mobile CTF

1st

First across the line in a national mobile application exploitation competition.

Tuwaiq Cyber Challenge · Reverse engineering

3rd

Third overall, and first blood on the reverse engineering track — first competitor to solve it.

Defensathon · Project SATE’

2nd

Second place for an AI-guided counter-UAS laser defence system — detection, tracking and low-cost interception.

CometChat · messaging platform

Stored XSS in group messages, reported privately and fixed by the vendor before anything was published here. CVE-2026-39154

Certifications · both operators

CRTO · OSCP+ · OSCP · eCDFP · CCNA · eCPPTv3 · eJPTv2. Earned, not collected.

Get in touch

Questions about the research, something to report, or an invitation to speak.