The XSS inside your favorite iOS app
How a default WKWebView implementation makes thousands of apps vulnerable to sandboxed HTML/CSS injection or XSS.
How a default WKWebView implementation makes thousands of apps vulnerable to sandboxed HTML/CSS injection or XSS.
V12 found two critical object-lifetime vulnerabilities that allow the untrusted host server to break the enclave boundary.
V12 found five vulnerabilities while reviewing Ambire Wallet v6.13.4, a browser extension for Ethereum and EVM networks.
We raised $10M from Electric Capital. We're building dangerously powerful offensive security tools, and recently won a $2.5M bug bounty—the largest bounty ever received by an AI agent.