
Vulnerability research write-ups — CVE-2026-12478 (libsoup), Apple WebKit, Google VRP
Vulnerability research write-ups. Every entry here corresponds to a fixed, publicly tracked issue — no theoretical findings.
Adel Bouachraoui — hydra.land · LinkedIn · YesWeHack
| Write-up | Target | Class | ID |
|---|---|---|---|
| When a security patch guards the wrong branch | GNOME libsoup | Out-of-bounds read (CWE-125) | CVE-2026-12478 |
Write-ups covering my Google VRP reports — memory safety in protobuf/upb, and CI/CD supply-chain and agent-trust issues in Google tooling — are held until disclosure is cleared through the program. Nine reports submitted since April 2026, two awarded.
Source-driven auditing over blind fuzzing. Two things I look for in particular:
Nothing is a finding until an exploit oracle fires. Severity is reported honestly, including when preconditions make a bug hard to reach.