Breaking down a client-side bug chain, impact proof, and safe remediation notes.
DOM Clobbering to Account Takeover
Blog
Write-ups, disclosure notes, CTF learnings, and practical security research logs.
Breaking down a client-side bug chain, impact proof, and safe remediation notes.
A repeatable approach for finding authorization gaps in modern API surfaces.
What changed between initial report, vendor coordination, patch release, and advisory.