Proof
Findings
Vulnerabilities I've found and disclosed responsibly — CVEs, advisories, and bug-bounty work within program scope. Each links to a writeup or advisory where one exists.
1 published CVE / advisories
Local privilege escalation to root in macOS PackageKit
A permissions issue in PackageKit, the macOS framework behind software installation, let a malicious app escalate to root. Apple fixed it in macOS Tahoe 26.4 by adding further restrictions.
Impact An app could gain root privileges — full local compromise of the machine (read/modify any data, persist, disable protections).
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
fixed