luke francis
portfolio.vm — ttyS0
booting linux

type help to look around.

this is a real linux terminal — best on a desktop with a keyboard. mobile works but typing help on a phone is a tax.

Luke Francis

Security researcher · 17 · New Braunfels, Texas

About

I find bugs in browsers, infrastructure, and codecs. Eleven published CVEs across Chrome, WebKit, etcd, Traefik, Envoy, and vm2. The work spans spec-compliance auditing, IPC trust-boundary analysis, sandbox escapes, and code review of widely deployed infrastructure.

Currently: WebKit exploit chain development and codec vulnerability research (libvpx, libaom).

Full research index · RSS

Published CVEs

  1. CVE-2026-3061 — Chrome H.264 PPS parser missing range validation. CVSS 9.1, zero-interaction via <video>. $10,000 Google VRP.
  2. CVE-2026-5902 — Chrome Android video encoder TOCTOU in shared memory. High severity. Patched within 24 hours.
  3. CVE-2026-5907 — Chrome H.264 range validation overflow. Second finding from extending the spec-compliance audit.
  4. CVE-2026-28962 — Apple WebKit WebContent sandbox escape. Unguarded IPC handler returned attacker-controlled file contents to compromised renderers, enabling arbitrary host file reads. Credited in iOS/iPadOS 26.5 and macOS Tahoe 26.5.
  5. CVE-2026-43725 — Apple WebKit sandbox boundary issue: a malicious website could process restricted web content outside the sandbox. Addressed with improved input validation. Credited on macOS Sonoma and macOS Sequoia.
  6. CVE-2026-33413 — etcd authorization bypass across multiple APIs (MemberList, Alarm, Lease, compaction). CVSS 8.8.
  7. CVE-2026-33343 — etcd nested transactions bypass RBAC entirely. CVSS 6.5.
  8. CVE-2026-31360 — Traefik SPIFFE trust-domain bypass: cert host overwrote expected host before comparison, enabling cross-trust-domain impersonation. MITRE-assigned; fix merged.
  9. CVE-2026-31361 — Traefik ACME private-key exposure: %+v logged full DER key on parse failure, a five-year unported regression. MITRE-assigned; fix merged.
  10. CVE-2026-6994 — Envoy query-parameter injection via header_mutation. Auth bypass and SQLi/XSS upstream. CVSS 6.3.
  11. CVE-2026-47698 — vm2 sandbox breakout via stacked call indirection around dangerous host prototype-mutator checks, enabling arbitrary host command execution. CVSS 9.8; fixed in 3.11.6. GitHub advisory; credited as a reporter.

Other research

Writeups

48 Hours on a SCADA Honeypot

WannaCry samples still propagating in 2026, Outlaw/mdrfckr botnet credential stuffing from Romania, Solana validator credential harvesting, automated Modbus/TCP scanning. Two days of captures from a SCADA-themed honeypot on Hetzner.

Contact

This page boots a real Linux kernel in your browser via v86. The interactive terminal is the canonical experience — this static layer exists for crawlers, screen readers, and visitors without JavaScript, as well as people who don't want to go through the hassle of the terminal.