23
46 posts



We got permission from the Samsung Security team to disclose this uXSS that we found in Samsung Browser, it was assigned a CVE (CVE-2025-58485) and patched. Here is the PoC, expect the write-up in the next upcoming days.

they decreased the bounty amount, I replies with my reasons and asked for a review, since it was a conditional RCE, they should have paid higher :]












به شاگردم میگم فیلم ۲۳ جیمکری رو ندیدی؟ بعد براش قلب سیاه زدم چون یوزرنیمش ۲۳ بود. برگشت گفت یاشار اون موقع که فیلم اومده ۳ سالم بوده، خدایی حق داره من پیر شدم 😂😂


I’ve been hunting on H1 for almost 3 years, ranked #18 in 2025, have always tried to contribute positively to the hacker community. I’ve earned around $500k in bounties and was on the road to $1M. Yet I don’t even have HSM, and I feel I haven’t been recognized as I should 1/4















