DongHa Lee's Home Page
Security researcher & vulnerability analyst
E-mail: p@sswd.pw Phone: +82 10 3025 9474 X / Twitter: @gap_dev Discord: lee_dongha
Profile
Security researcher and vulnerability analyst specializing in fuzzing, AI security, reversing, and exploit development.
Published multiple CVEs across Apple, Chromium, Nvidia CUDA Toolkit, Adobe, Autodesk, and open-source ecosystems.
Active contributor to international security conferences, academic research, and open-source fuzzing communities.
Technical skills
Vulnerability Research
Languages
Systems
Experience
(4)Software Security Assessment Lab (SSA LAB)
Feb. 2025 — Present- Conducting advanced vulnerability research in fuzzing, attack surface discovery, and automated exploitation.
- Contributing to multiple security publications and national-level cybersecurity research projects.
ENKI WhiteHat
Aug. 2024 — Dec. 2024- Conducted R&D on large-scale exploit detection and vulnerability analysis across diverse software targets.
- Built data-processing pipelines to handle high-volume security telemetry and vulnerability datasets.
- Developed and evaluated AI-based models for automated exploit classification and attack pattern detection.
Self-Employed Startup
Jun. 2023 — Aug. 2024- Led offensive security consulting and penetration testing engagements for organizations and research clients.
- Delivered vulnerability assessments across embedded, IoT, and enterprise environments.
Published CVEs
(31)Select an entry to read its full disclosure.
CVE-2026-85062 ReDoS in Colord NPM module
!!My First Bug in 2023!! ReDoS in Colord NPM module
CVE-2026-28817 Apple Print (+$20,000 reward)
Apple macOS/IOS/etc Tahoe 26.3 Print (+$20000 reward)
CVE-2026-28868 Apple XNU Kernel (+$1,000 reward)
Apple XNU Kernel Tahoe 26.3 (+$1000 reward)
CVE-2026-20695 Apple XNU Kernel
ZDI-CAN-28499, Apple XNU Kernel Tahoe 26.3
CVE-2025-23339 Nvidia CUDA Toolkit Vulnerability
Nvidia CUDA Toolkit Vulnerability
CVE-2025-43511 Apple WebKit GPU Vulnerability (+$1,000 reward)
Apple WebKit GPU Vulnerability (+$1000 reward)
CVE-2025-43401 Apple CoreAnimation Vulnerability
Apple Tahoe 26.1 CoreAnimation Vulnerability
CVE-2025-10500 Chromium GPU Vulnerability (+$15,000 reward)
Chromium GPU Vulnerability (+$15000 reward)
CVE-2025-43287 Apple ImageIO
Apple Tahoe 26.0 ImageIO
CVE-2025-43372 Apple CoreMedia (+$1,000 reward)
Apple Tahoe 26.0 CoreMedia (+$1000 reward)
CVE-2025-43338 Apple ImageIO (+$1,000 reward)
Apple Tahoe 26.0 ImageIO (+$1000 reward)
CVE-2025-53015 XMP Profile Parsing Bug
CVSS 7.5 / CWE-835 / XMP Profile Parsing Bug
CVE-2025-24184 Apple CoreMedia Playback
Apple CoreMedia Playback (iOS 18.3 / macOS Sequoia 15.3)
CVE-2025-4605 Autodesk MAYA 2025 Memory Corruption
CVSS 5.5 / CWE-789 / Autodesk MAYA 2025 Memory Corruption
CVE-2024-44915 Improper Access Control
CVSS 5.5 / CWE-284 / Improper Access Control
CVE-2024-44914 Improper Access Control
CVSS 5.5 / CWE-284 / Improper Access Control
CVE-2024-44913 Improper Access Control
CVSS 5.5 / CWE-284 / Improper Access Control
CVE-2024-45872 Heap-based Buffer Overflow
CVSS 6.3 / CWE-122 / Heap-based Buffer Overflow
CVE-2024-45871 Improper Input Validation
CVSS 6.3 / CWE-20 / Improper Input Validation
CVE-2024-45870 Improper Access Control
CVSS 6.5 / CWE-284 / Improper Access Control
KVE-2024-0454 KISA KNVD Disclosure Report
KISA KNVD Disclosure Report
KVE-2024-0821 Find the Gap Private Bug Bounty Report
Find the Gap Private Bug Bounty Report
KVE-2024-0820 Find the Gap Private Bug Bounty Report
Find the Gap Private Bug Bounty Report
CVE-2024-42358 Denial-of-Service via Infinite Loop
CVSS 5.5 / CWE-835 / Denial-of-Service via Infinite Loop
CVE-2024-20746 Adobe Premiere Pro Out-of-Bounds Write
CVSS 7.8 / CWE-787 / Adobe Premiere Pro Out-of-Bounds Write
CVE-2024-27088 es5-ext ReDoS
CVSS 5.5 / CWE-400, CWE-1333 / es5-ext ReDoS
CVE-2024-22526 Buffer Copy Without Size Check
CVSS 5.5 / CWE-120 / Buffer Copy Without Size Check
CVE-2024-23339 Prototype Pollution
CVSS 6.5 / CWE-1321 / Prototype Pollution
CVE-2023-50245 Buffer Copy Without Size Check
CVSS 9.8 / CWE-120 / Buffer Copy Without Size Check
CVE-2023-45827 Prototype Pollution
CVSS 9.8 / CWE-1321 / Prototype Pollution
CVE-2023-43646 Regular Expression DoS
CVSS 7.5 / CWE-400, CWE-1333 / Regular Expression DoS
- CVE-2026-85062 — !!My First Bug in 2023!! ReDoS in Colord NPM module
- CVE-2026-28817 — Apple macOS/IOS/etc Tahoe 26.3 Print (+$20000 reward)
- CVE-2026-28868 — Apple XNU Kernel Tahoe 26.3 (+$1000 reward)
- CVE-2026-20695 — ZDI-CAN-28499, Apple XNU Kernel Tahoe 26.3
- CVE-2025-23339 — Nvidia CUDA Toolkit Vulnerability
- CVE-2025-43511 — Apple WebKit GPU Vulnerability (+$1000 reward)
- CVE-2025-43401 — Apple Tahoe 26.1 CoreAnimation Vulnerability
- CVE-2025-10500 — Chromium GPU Vulnerability (+$15000 reward)
- CVE-2025-43287 — Apple Tahoe 26.0 ImageIO
- CVE-2025-43372 — Apple Tahoe 26.0 CoreMedia (+$1000 reward)
- CVE-2025-43338 — Apple Tahoe 26.0 ImageIO (+$1000 reward)
- CVE-2025-53015 — CVSS 7.5 / CWE-835 / XMP Profile Parsing Bug
- CVE-2025-24184 — Apple CoreMedia Playback (iOS 18.3 / macOS Sequoia 15.3)
- CVE-2025-4605 — CVSS 5.5 / CWE-789 / Autodesk MAYA 2025 Memory Corruption
- CVE-2024-44915 — CVSS 5.5 / CWE-284 / Improper Access Control
- CVE-2024-44914 — CVSS 5.5 / CWE-284 / Improper Access Control
- CVE-2024-44913 — CVSS 5.5 / CWE-284 / Improper Access Control
- CVE-2024-45872 — CVSS 6.3 / CWE-122 / Heap-based Buffer Overflow
- CVE-2024-45871 — CVSS 6.3 / CWE-20 / Improper Input Validation
- CVE-2024-45870 — CVSS 6.5 / CWE-284 / Improper Access Control
- KVE-2024-0454 — KISA KNVD Disclosure Report
- KVE-2024-0821 — Find the Gap Private Bug Bounty Report
- KVE-2024-0820 — Find the Gap Private Bug Bounty Report
- CVE-2024-42358 — CVSS 5.5 / CWE-835 / Denial-of-Service via Infinite Loop
- CVE-2024-20746 — CVSS 7.8 / CWE-787 / Adobe Premiere Pro Out-of-Bounds Write
- CVE-2024-27088 — CVSS 5.5 / CWE-400, CWE-1333 / es5-ext ReDoS
- CVE-2024-22526 — CVSS 5.5 / CWE-120 / Buffer Copy Without Size Check
- CVE-2024-23339 — CVSS 6.5 / CWE-1321 / Prototype Pollution
- CVE-2023-50245 — CVSS 9.8 / CWE-120 / Buffer Copy Without Size Check
- CVE-2023-45827 — CVSS 9.8 / CWE-1321 / Prototype Pollution
- CVE-2023-43646 — CVSS 7.5 / CWE-400, CWE-1333 / Regular Expression DoS
Presentations & lectures
(8)Fuzzing & Symbolic Execution — CCA National Information Security Seminar (Feb. 2025)
Metaverse Fuzzing for 0-day Discovery — KUCIS Regional Seminar (Oct. 2024)
Main Instructor, KISA Academy Bug Hunting Master Course (Jun. 2024)
AddressSanitizer and Out-of-Bounds Vulnerabilities — CCA Seminar (Mar. 2024)
Offensive Security Study Lecturer (2024)
Teaching Assistant, Network Security Laboratory Course (2024)
ReDoS Detection Tool Research Presentation — Korea Institute of Information Security (Nov. 2023)
Automated ReDoS Discovery Methodology — KUCIS Seminar (Sep. 2023)
Papers
(11)LLM Agent-Driven Honeypot Smart Contract Detection Using Symbolic Execution — Korea Institute of Information Security [PDF]
Constructing a Public Framework-XPC Service Dependency Graph via Undocumented macOS Interface Identification for Attack Surface Analysis — KCI Journal [PDF]
Hybrid Fuzzing Research Trends and Technical Challenges — Korea Institute of Information Security
Android Fuzzing Harness Generation via Static and Dynamic Analysis — Korea Institute of Information Security
LLM-based Software Vulnerability Analysis Research Trends — Korea Institute of Information Security
Automated macOS Attack Surface Identification using XPC and IOKit — Korea Institute of Information Security [PDF]
Attack Surface and Vulnerability Analysis of ARM Virtualization — KTCCS (KCI Journal) [PDF]
Symbol Porting Techniques for macOS Kernel Debugging — Korea Information Processing Society [PDF]
Binary-only Fuzzing Performance Improvement via Corpus Transfer — Korea Institute of Information Security [PDF]
ReDoS Detection Tool Trend Analysis and Improvement — Korea Institute of Information Security [PDF]
Node.js Package Vulnerability Research via Prototype Pollution Pattern Study — Korea Institute of Information Security [PDF]
Paper previews
First pages. Select a paper to open the complete PDF in a new tab.
LLM Agent-Driven Honeypot Smart Contract Detection Using Symbolic Execution
Public Framework–XPC Service Dependency Graph & Attack Surface Analysis
Automated macOS Attack Surface Identification via XPC and IOKit
Towards Automated Vulnerability Analysis in ARM-based Virtualization
Symbol Transplantation for macOS Kernel Debugging
Enhancing Binary-only Fuzzing for Commercial Software via Corpus Transfer
Analysis and Improvement of ReDoS Vulnerability Detection Tools
Node.js Packages Vulnerability Analysis via Prototype Pollution Patterns
Projects
(9)Finding Vulnerabilities in Silicon macOS Virtualization
Contributor to AFL++ open-source fuzzing framework
LKL GPU Kernel Driver Fuzzing Project (2024)
Member, Hspace Knights Security Activities (2024)
ReBoB / NodeBOB Vulnerability Research Team (2023)
CTF Challenge Authoring and Competition Operations
Smart Transportation IoT Device Vulnerability Analysis Project
Enterprise Penetration Testing and Security Consulting Engagements
Multiple Government and Industry R&D Security Projects
Awards
(14)DEFCON 34 FINAL, 7th Place (Aug. 2026)
SekaiCTF 2026, 7th Place (Jun. 2026)
DEFCON 34 CTF Qualifier, 6th Place (May 2026)
TJCTF 2026, 1st Place (May 2026)
CODEGATE 2026 Qualifier CTF General, 4th Place (Mar. 2026)
Selected for the Apple Security Research Device Program and received a Security Research Device (2026)
Best Paper Award — Korea Institute of Information Security (Nov. 2025)
TS Penetration Testing Competition, 4th Place — Korea Transportation Safety Authority (Nov. 2025)
Woori Bank Wooricon Hacking Competition, 1st Place (Sep. 2025)
WagleWagle Hackathon, 1st Place (Feb. 2024)
Gachon University Talent Award (Nov. 2023)
Best Paper Award — Korea Institute of Information Security (Nov. 2023)
Information Security Policy Proposal Competition, Finalist (Oct. 2023)
WagleWagle Hackathon, 3rd Place (Sep. 2023)
Education
(2)Best of the Best (BoB) 14th
Jul. 2025 — Dec. 2025Gachon University
2023 — PresentSelected open-source projects & contributions
(7)LibAFL_vifuzz
LibAFL-based work for macOS binary-only fuzzing, providing instrumentation and fuzzing capabilities used as the foundation for ViFuzz development.
MacOS-UserlandAttackSurface-visualization
Automated macOS userland attack-surface analysis and visualization. Analyzes Frameworks, XPC/Mach Services, Objective-C imports/exports, and dlopen relationships to graph attack surfaces and dependencies.
hyfervisor
Virtualization Framework-based environment for macOS kernel live debugging on Apple Silicon. Supports custom XNU/Kext and KASAN kernel booting, as well as a GDB debug stub.
MacOs-Bootloader-Patch-Tools
Boot-chain patching tools for booting custom kernels and Kexts in Apple Silicon VMs. Automates AVPBooter → LLB → iBoot → Kernel Cache patching.
MacOs-KSANCOV-coverage-tools
Kernel coverage measurement and analysis using XNU's /dev/ksancov, including PC/edge coverage and per-Kext coverage analysis.
MacOS-kext-visualization
Analysis and visualization of macOS Kext structures and dependencies, including Kext dependency graphs and comparisons between host and VM environments.