Blog
Research notes, technical writing, and security posts.
Two bugs that only mattered together: hunting root in the Flatpak system helper
The story of finding a path traversal in the Flatpak system helper, chaining it with a second write primitive to reach root, a dead end that ate a day, and the twist at disclosure when one of the two bugs turned out to already be known.
flatpak / vulnerability-research / privilege-escalation / path-traversal
11 min readFour Hours, Four Bytes: Hunting Down CVE-2026-18649
The full story of finding an unbounded memory growth bug in GStreamer's RTP depayloader, including the seven attempts that failed before the exploit worked.
gstreamer / rtp / dos / vulnerability-research / cve
13 min read