I’m Hyunwoo Kim (@v4bel), an independent vulnerability researcher.

Awards

  • Google kvmCTF 0-day Winner (CVE-2026-53359)
  • Pwnie Awards 2025 Best Privilege Escalation category Winner (CVE-2024-50264)
  • Pwn2Own Berlin 2026 Red Hat Linux in the LPE category Winner ($5,000)
  • Pwn2Own Berlin 2025 Red Hat Linux in the LPE category Winner (Theori, $15,000)
  • Google kernelCTF LTS-6.6.75/COS-105 1-day Winner (CVE-2025-21756, $71,337)
  • Google kernelCTF LTS-6.6.56/COS-109 0-day Winner (CVE-2024-50264, $81,337)
  • Google kernelCTF LTS-6.6.35 0-day Winner (CVE-2024-41010, $51,337)

Vulnerability Reports

Android
  • CVE-2026-21048/SVE-2026-1650 (Samsung Galaxy libimagecodec.media.quram.so 0-click/1-click Out-Of-Bounds Write)
  • CVE-2026-21049/SVE-2026-1820 (Samsung Galaxy libpadm.so Out-Of-Bounds Write)
KVM
  • CVE-2026-64561 (Guest-to-Host Escape in KVM/x86, Zapscape)
  • CVE-2026-53359 (Guest-to-Host Escape in KVM/x86, Januscape)
  • CVE-2026-46316 (Guest-to-Host Escape in KVM/arm64, ITScape)
Linux Kernel
  • CVE-2026-43284 (Linux Kernel xfrm-ESP Page-Cache Write, Dirty Frag)
  • CVE-2026-43500 (Linux Kernel RxRPC Page-Cache Write, Dirty Frag)
  • CVE-2026-43503 (Linux Kernel xfrm-ESP Page-Cache Write, Dirty Frag Variant)
  • CVE-2026-23239 (Linux Kernel ESP-in-TCP Use-After-Free, Out-of-Cancel)
  • CVE-2026-23240 (Linux Kernel kTLS Use-After-Free, Out-of-Cancel)
  • CVE-2026-23393 (Linux Kernel Bridge CFM Use-After-Free, Out-of-Cancel)
  • CVE-2026-31406 (Linux Kernel XFRM Use-After-Free, Out-of-Cancel)
  • CVE-2026-31407 (Linux Kernel Netfilter Out-Of-Bounds)
  • CVE-2026-23458 (Linux Kernel Netfilter Use-After-Free)
  • CVE-2026-31414 (Linux Kernel Netfilter Use-After-Free)
  • CVE-2025-38087 (Linux Kernel Traffic Control TAPRIO Use-After-Free)
  • CVE-2024-50264 (Linux Kernel Virtual Socket Use-After-Free)
  • CVE-2024-27394 (Linux Kernel TCP Use-After-Free)
  • CVE-2024-27395 (Linux Kernel OpenvSwitch Use-After-Free)
  • CVE-2024-27396 (Linux Kernel GTP Use-After-Free)
  • CVE-2023-51779 (Linux Kernel Bluetooth Socket Use-After-Free)
  • CVE-2023-51780 (Linux Kernel ATM Socket Use-After-Free)
  • CVE-2023-51781 (Linux Kernel Appletalk Socket Use-After-Free)
  • CVE-2023-51782 (Linux Kernel Rose Socket Use-After-Free)
  • CVE-2023-32269 (Linux Kernel NET/ROM Socket Use-After-Free)
  • CVE-2022-41218 (Linux Kernel DVB Core Use-After-Free)
  • CVE-2022-45884 (Linux Kernel DVB Core Use-After-Free)
  • CVE-2022-45885 (Linux Kernel DVB Core Use-After-Free)
  • CVE-2022-45886 (Linux Kernel DVB Core Use-After-Free)
  • CVE-2022-45919 (Linux Kernel DVB Core Use-After-Free)

Conference Talks

  • Race Condition Symphony: From Tiny Idea to PwniePOC Conference, Seoul, 2025