I'm CMD, a student with a passion for everything computers, science, engineering and technology.
As a student, I continue to acquire new knowledge, but I like to try to apply my learnings in practical situations, such as Bug Bounty / CVD programs. I have reported 20+ vulnerabilities to Apple, out of which 12+ received CVE IDs.
Here are the most significant ones so far (in my opinion):
- CVE-2025-43398 - Kernel (Apple XNU)
- CVE-2025-43399, CVE-2025-43367, CVE-2024-44200 - Siri sensitive information disclosures
Full list of contributions & fixed versions
- CVE-2025-43398 - Kernel (Apple XNU), addressed in iOS 26.1
- CVE-2025-43399 - Siri, addressed in macOS 26.1
- CVE-2025-43367 - Siri, addressed in macOS 26
- CVE-2025-24263 - Apple StickerKit, addressed in macOS 15.4
- CVE-2024-44200 - Siri, addressed in iOS 18.1
- CVE-2024-44170 - Siri, addressed in iOS 18.0
- Additional recognition - Apple Maps, addressed in iOS 18.0
- Additional recognition - Apple Shortcuts, addressed in iOS 18.0
- CVE-2024-40838 - macOS Notification Center, addressed in macOS 15.0
- Additional recognition - Apple Core Services - macOS 15.0
- Additional recognition - Apple Sandbox - macOS 15.0
- CVE-2024-23243 - Accessibility, addressed in iOS 17.4
- Additional recognition - AirDrop, addressed in iOS 17.4
- CVE-2023-42878 - Share Sheet, addressed in iOS 17.1
- CVE-2023-41254 - Apple Weather, addressed in iOS 17.1
- Apple Web Server Security Acknowledgements - October 2023
- Additional recognition - Apple Shortcuts, addressed in iOS 17.0
- CVE-2023-42943 - Clock (Apple), addressed in macOS 14.0
- Additional recognition - Apple Shortcuts, addressed in iOS 16.3
- CVE-2022-32938 - Apple Shortcuts, addressed in iOS 16.1



