Abdulaziz Alasaiqah

Abdulaziz Alasaiqah

Penetration Tester & Bug Bounty Hunter, Riyadh

16-year-old security researcher. Five published CVEs, four in Firefox and fixed by Mozilla. 132 reports and 1,500 points on BugBounty.sa.

Published CVEs & writeups

Use-after-free in RasterImage surface discard

A cross-thread check-then-AddRef race in image surface discard resurrects a freed RasterImage, a content-process use-after-free reachable from a web page.

Read writeup

Stored XSS in CometChat group messages

A persistent JavaScript payload in group messages executes in the browser of every member who opens the conversation.

Read writeup

Uninitialized heap disclosure through a crafted web font

A crafted @font-face leaves an uninitialized-heap gap in the sanitized font; measuring a character leaks process memory two bytes at a time.

Read writeup

Test-only FormAutofill handlers exposed in production

Four test-only message handlers shipped in Firefox let any compromised renderer read, inject, or delete saved autofill data.

Read writeup

Fission site-isolation bypass via missing PipelineId namespace check

A compromised content process forges a WebRender PipelineId namespace to hijack another origin's image pipeline, bypassing Fission site isolation.

Read writeup