About Me

I’m a PhD Student at HexHive@EPFL, advised by Prof. Mathias Payer. I received my master degree in University of Chinese Academy of Science in 2023 and my bachelor in Xidian University in 2020. I’m broadly interested in Software and System security, particularly in Browser Security and Fuzzing.

Besides the research, I actively contribute to open source community by submitting bug reports and intergrating my research prototypes. So far I reported more than 50 CVEs for widely used open source software and integrated my research prototypes in AFL++[1], one of the most widely used greybox fuzzing framework.

I enjoy bug hunting on complex software system for fun and profits. By leveraging static analysis, fuzzing and code auditing, I successfully found a series of vulnerbilities in web browsers and rank #42 in Google VRP 2024, receiving 25,000 USD bug bounties.

Selected Publication

[1] MendelFuzz: The Return of the Deterministic Stage, ESEC/FSE’25

[2] FishFuzz: Catch Deeper Bugs by Throwing Larger Nets, USENIX Sec’23

Bug Hunting

VendorBugSeverity 
ChromeOSb/385851796HighGlobal-Buffer-Overflow in Virglrenderer
ChromeCVE-2025-0438HighStack-Buffer-Overflow in Tracing
ChromeCVE-2025-0436HighInteger Overflow in Skia
Chromeb/365802556HighUse-After-Return in Blink
ChromeCVE-2024-7968HighUse-After-Free in UI
Chromeb/351843813MediumUse-After-Free in UI
ChromeCVE-2024-5847MediumUse-After-Free in PDF
ChromeCVE-2024-5846MediumUse-After-Free in PDF
ChromeCVE-2024-7018MediumHeap-Buffer-Overflow in PDF
WiresharkCVE-2024-0210UnknownDoS in Wireshark dissector
WiresharkCVE-2024-0209UnknownDoS in Wireshark dissector
AppleCVE-2022-26981UnknownGlobal-Buffer-Overflow in Font
HuaweiCVE-2022-31783UnknownGlobal-Buffer-Overflow in Font