Skip to content

Proof

Findings

Vulnerabilities I've found and disclosed responsibly — CVEs, advisories, and bug-bounty work within program scope. Each links to a writeup or advisory where one exists.

1 published CVE / advisories

high CVE-2026-28840 CVSS 7.8 Apple

Local privilege escalation to root in macOS PackageKit

A permissions issue in PackageKit, the macOS framework behind software installation, let a malicious app escalate to root. Apple fixed it in macOS Tahoe 26.4 by adding further restrictions.

Impact An app could gain root privileges — full local compromise of the machine (read/modify any data, persist, disable protections).

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

fixed