Deep research.
Machine‑scale
discovery.

RaxSec pairs hands-on vulnerability research with AI-driven tooling to find, verify, and responsibly disclose flaws in complex software, from browser engines to the boundaries meant to contain them.

Public CVEs
24
Critical
12
Mozilla HoF
Q2 · Q3 ’26
24Public CVE credits
12Critical-rated

Two disciplines.
One research practice.

Security research & development

Deep, hands-on investigation of complex software and the boundaries that protect it. We study design assumptions, trace root causes, and turn findings into fixes vendors can ship.

  • Vulnerability research in browsers & complex runtimes
  • Memory safety & sandbox boundary analysis
  • Root-cause analysis & proof-of-concept development
  • Coordinated vulnerability disclosure
Discuss a research engagement

AI-driven research

We build and use AI-assisted pipelines that extend a researcher’s reach. They read more code, generate more hypotheses, and surface patterns that are easy to miss by hand.

  • LLM-assisted code auditing
  • AI-guided fuzzing & harness generation
  • Variant analysis across large codebases
  • Automated triage & crash deduplication
Talk about AI-driven research

AI accelerates. Humans verify.

The work.
On record.

Severity mixCVSS 3.1 · all records
  • Critical 12
  • High 8
  • Medium 4
Average score
8.5
Highest score
9.8
Components
13
Disclosures by monthPublished CVEs · 2026
Vulnerability index 24
Public CVEs credited to Yaqoub Aldurayhim. Expand a finding to see its products and advisory.
CVE IDFinding / ComponentCVSSPublished
CVE-2026-100811Published
Use-after-free / sandbox escapeDOM: Core & HTML

Products: Firefox, Thunderbird

Research area: Memory safety

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
9.6critical
CVE-2026-100803Published
Same-origin policy bypassWebExtensions

Products: Firefox, Thunderbird

Research area: Security boundaries

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
8.1high
CVE-2026-100768Published
Use-after-freeGraphics: WebGPU

Products: Firefox, Thunderbird

Research area: Memory safety

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
8.8high
CVE-2026-100762Published
Use-after-free / sandbox escapeDOM: Content Processes

Products: Firefox, Thunderbird

Research area: Memory safety

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
9.6critical
CVE-2026-84129Published
Site isolation issueDOM: Navigation

Products: Firefox, Thunderbird

Research area: Security boundaries

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
9.8critical
CVE-2026-84125Published
Use-after-freeDOM: Core & HTML

Products: Firefox, Thunderbird

Research area: Memory safety

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
5.4medium
CVE-2026-84123Published
Use-after-free / privilege escalationGraphics: WebGPU

Products: Firefox, Thunderbird

Research area: Memory safety

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
8.8high
CVE-2026-84121Published
Use-after-free / sandbox escapeDOM: Security

Products: Firefox, Thunderbird

Research area: Memory safety

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
9.6critical
CVE-2026-84119Published
Use-after-free / sandbox escapeDOM: Navigation

Products: Firefox, Thunderbird

Research area: Memory safety

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
9.6critical
CVE-2026-74962Published
Site isolation issueNetworking: Cookies

Products: Firefox, Thunderbird

Research area: Security boundaries

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
8.1high
CVE-2026-74948Published
Information disclosureGraphics

Products: Firefox, Thunderbird

Research area: Information disclosure

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
6.5medium
CVE-2026-74935Published
Privilege escalationDOM: Networking

Products: Firefox, Thunderbird

Research area: Security boundaries

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
8.8high
CVE-2026-16405Published
Information disclosureNetworking: WebSockets

Products: Firefox, Thunderbird

Research area: Information disclosure

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
7.5high
CVE-2026-16399Published
Site isolation issueDOM: Navigation

Products: Firefox, Thunderbird

Research area: Security boundaries

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
7.5high
CVE-2026-16388Published
Sandbox escapeDOM: Networking

Products: Firefox, Thunderbird

Research area: Security boundaries

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
9.8critical
CVE-2026-16382Published
Mitigation bypassDOM: Service Workers

Products: Firefox, Thunderbird

Research area: Security boundaries

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
9.8critical
CVE-2026-16351Published
Use-after-free / sandbox escapeDOM: Navigation

Products: Firefox, Thunderbird

Research area: Memory safety

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
9.8critical
CVE-2026-12311Published
Information disclosure, sandbox escapeSecurity: Process Sandboxing

Products: Firefox, Thunderbird

Research area: Security boundaries

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
4.7medium
CVE-2026-12309Published
Memory safety bug fixed in Firefox 152Firefox · Memory safety

Products: Firefox, Thunderbird

Research area: Memory safety

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
6.5medium
CVE-2026-12304Published
Same-origin policy bypassNetworking: Cookies

Products: Firefox, Thunderbird

Research area: Security boundaries

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
9.1critical
CVE-2026-12296Published
Sandbox escapeSecurity: Process Sandboxing

Products: Firefox, Thunderbird

Research area: Security boundaries

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
9.6critical
CVE-2026-12295Published
Sandbox escapeDOM: Navigation

Products: Firefox, Thunderbird

Research area: Security boundaries

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
9.6critical
CVE-2026-8958Published
Information disclosure, sandbox escapeSecurity: Process Sandboxing

Products: Firefox, Thunderbird

Research area: Security boundaries

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
8.6high
CVE-2026-8956Published
Integer overflowNetworking: JAR

Products: Firefox, Thunderbird

Research area: Memory safety

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
9.8critical

Every assumption
is worth testing.

Yaqoub Aldurayhim

Founder · RaxSec

I founded RaxSec around a simple principle: understanding a system deeply is the first step toward securing it. My public research focuses on browser security: memory safety, sandbox escapes, and site-isolation boundaries. It has been recognized by Mozilla’s Security Bug Bounty Hall of Fame.

Today, RaxSec pairs that hands-on work with AI-driven tooling, so more code can be examined without lowering the bar for what counts as a real finding.

View public research credits
Recognition mozilla: Security Bug Bounty Hall of Fame Yaqoub Aldurayhim Q2 2026Q3 2026 View recognition

A hard security problem?
Let’s look closer.

Research collaborations, security R&D, and AI-driven vulnerability research.

contact@raxsec.com