Observed arrival · 2026-09-01
cli0ck: Five CVEs, documented before disclosure
A two-person Riyadh vulnerability-research team publishes write-ups on bugs found in Firefox, CometChat, and related software.
Field notes
The team describes a disclosure workflow built around target selection, minimized reproducers, root-cause analysis, and private vendor reporting before publication. Its visible record spans Firefox internals and CometChat, including a content-process use-after-free rated CVSS 9.8 and a persistent group-message XSS. The page also places the work in a competitive-research context, citing results from the Tuwaiq Cyber Challenge, Black Hat MEA 2025, and Tuwaiq Mobile CTF.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue