Independent vulnerability research.
We find and report security flaws in browsers, operating systems, and developer tooling. Findings go to the vendor first, under their disclosure process, and are published here only after a fix ships.
Current focus
- WebKit and Safari. Cross-origin boundaries in the GPU and media pipelines, and the process model that backs them.
- macOS platform security. Entitlement surfaces and inter-process boundaries reachable from web content.
- Developer tooling and AI agent infrastructure. Trust boundaries in toolchains that execute untrusted input.
Lead researcher
Merrick Hare
Research, disclosure, and vendor coordination. Credited by Apple in the Safari 26.5.2 security release. More at merrickhare.com.
Disclosure
Vulnerabilities are reported directly to the vendor and held until a fix ships. We do not sell findings, and we do not publish details, proof-of-concept code, or vendor case references before remediation.
Advisories are published after the patch is generally available and independently verified against the shipped build.
Contact
For vendor security teams and coordinated disclosure. We are not taking on general consulting work.