INDEPENDENT THINKING. OFFENSIVE PERSPECTIVE.R&D / RED TEAM

Deep research.
Real resilience.

We study how systems fail to help you make them stronger. Security research and authorized red team services, grounded in evidence.

RaxSec R emblem
RAXSEC
24Public CVE creditsYaqoub Aldurayhim · GCVE
02Mozilla recognitionsHall of Fame · Q2 & Q3 2026
R&DAt the core of our workResearch informs every engagement

Understand the risk.
Improve the defense.

From the internals of software to the systems around it, we turn security questions into actionable findings.

Security research
& development

Focused investigation of software and its security boundaries. We examine design assumptions, analyze vulnerabilities, and translate research into practical remediation.

  • Vulnerability research
  • Software & security boundary analysis
  • Coordinated vulnerability disclosure
Discuss a research engagement

Red team
services

Objective-led, authorized assessments of your defenses. We work within an agreed scope to examine exposure, evaluate response, and identify opportunities to improve.

  • Scoped adversary simulation
  • Security control validation
  • Findings, remediation & retesting
Discuss a red team engagement

The work. On record.

Vulnerability index 24
Public CVEs credited to Yaqoub Aldurayhim. Expand a finding to see its products and advisory.
CVE IDFinding / ComponentCVSSPublished
CVE-2026-100811Published
Use-after-free / sandbox escapeDOM: Core & HTML

Products: Firefox, Thunderbird

Research area: Memory safety

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
9.6critical
CVE-2026-100803Published
Same-origin policy bypassWebExtensions

Products: Firefox, Thunderbird

Research area: Security boundaries

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
8.1high
CVE-2026-100768Published
Use-after-freeGraphics: WebGPU

Products: Firefox, Thunderbird

Research area: Memory safety

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
8.8high
CVE-2026-100762Published
Use-after-free / sandbox escapeDOM: Content Processes

Products: Firefox, Thunderbird

Research area: Memory safety

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
9.6critical
CVE-2026-84129Published
Site isolation issueDOM: Navigation

Products: Firefox, Thunderbird

Research area: Security boundaries

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
9.8critical
CVE-2026-84125Published
Use-after-freeDOM: Core & HTML

Products: Firefox, Thunderbird

Research area: Memory safety

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
5.4medium
CVE-2026-84123Published
Use-after-free / privilege escalationGraphics: WebGPU

Products: Firefox, Thunderbird

Research area: Memory safety

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
8.8high
CVE-2026-84121Published
Use-after-free / sandbox escapeDOM: Security

Products: Firefox, Thunderbird

Research area: Memory safety

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
9.6critical
CVE-2026-84119Published
Use-after-free / sandbox escapeDOM: Navigation

Products: Firefox, Thunderbird

Research area: Memory safety

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
9.6critical
CVE-2026-74962Published
Site isolation issueNetworking: Cookies

Products: Firefox, Thunderbird

Research area: Security boundaries

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
8.1high
CVE-2026-74948Published
Information disclosureGraphics

Products: Firefox, Thunderbird

Research area: Information disclosure

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
6.5medium
CVE-2026-74935Published
Privilege escalationDOM: Networking

Products: Firefox, Thunderbird

Research area: Security boundaries

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
8.8high
CVE-2026-16405Published
Information disclosureNetworking: WebSockets

Products: Firefox, Thunderbird

Research area: Information disclosure

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
7.5high
CVE-2026-16399Published
Site isolation issueDOM: Navigation

Products: Firefox, Thunderbird

Research area: Security boundaries

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
7.5high
CVE-2026-16388Published
Sandbox escapeDOM: Networking

Products: Firefox, Thunderbird

Research area: Security boundaries

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
9.8critical
CVE-2026-16382Published
Mitigation bypassDOM: Service Workers

Products: Firefox, Thunderbird

Research area: Security boundaries

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
9.8critical
CVE-2026-16351Published
Use-after-free / sandbox escapeDOM: Navigation

Products: Firefox, Thunderbird

Research area: Memory safety

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
9.8critical
CVE-2026-12311Published
Information disclosure, sandbox escapeSecurity: Process Sandboxing

Products: Firefox, Thunderbird

Research area: Security boundaries

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
4.7medium
CVE-2026-12309Published
Memory safety bug fixed in Firefox 152Firefox · Memory safety

Products: Firefox, Thunderbird

Research area: Memory safety

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
6.5medium
CVE-2026-12304Published
Same-origin policy bypassNetworking: Cookies

Products: Firefox, Thunderbird

Research area: Security boundaries

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
9.1critical
CVE-2026-12296Published
Sandbox escapeSecurity: Process Sandboxing

Products: Firefox, Thunderbird

Research area: Security boundaries

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
9.6critical
CVE-2026-12295Published
Sandbox escapeDOM: Navigation

Products: Firefox, Thunderbird

Research area: Security boundaries

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
9.6critical
CVE-2026-8958Published
Information disclosure, sandbox escapeSecurity: Process Sandboxing

Products: Firefox, Thunderbird

Research area: Security boundaries

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
8.6high
CVE-2026-8956Published
Integer overflowNetworking: JAR

Products: Firefox, Thunderbird

Research area: Memory safety

Credited researcher: Yaqoub Aldurayhim

Score source: CISA-ADP · CVSS 3.1

Read Mozilla advisory
9.8critical

Every assumption
is worth testing.

Yaqoub Aldurayhim

Founder · RaxSec

I founded RaxSec around a simple principle: understanding a system deeply is the first step toward securing it. My public research includes browser security vulnerabilities and contributions recognized by Mozilla.

RaxSec brings that research perspective to security R&D and red team engagements, with clear scope, documented findings, and practical recommendations.

View my public research credits
mozilla:Security Bug Bounty Hall of FameYaqoub AldurayhimQ2 2026Q3 2026View recognition
START A CONVERSATION

A hard security problem?
Let’s look closer.

contact@raxsec.com