Luke Francis
Security researcher · 17 · New Braunfels, Texas
About
I find bugs in browsers, infrastructure, and codecs. Eleven published CVEs across Chrome, WebKit, etcd, Traefik, Envoy, and vm2. The work spans spec-compliance auditing, IPC trust-boundary analysis, sandbox escapes, and code review of widely deployed infrastructure.
Currently: WebKit exploit chain development and codec vulnerability research (libvpx, libaom).
Full research index · RSS
Published CVEs
- CVE-2026-3061 — Chrome H.264 PPS parser missing range validation. CVSS 9.1, zero-interaction via
<video>. $10,000 Google VRP. - CVE-2026-5902 — Chrome Android video encoder TOCTOU in shared memory. High severity. Patched within 24 hours.
- CVE-2026-5907 — Chrome H.264 range validation overflow. Second finding from extending the spec-compliance audit.
- CVE-2026-28962 — Apple WebKit WebContent sandbox escape. Unguarded IPC handler returned attacker-controlled file contents to compromised renderers, enabling arbitrary host file reads. Credited in iOS/iPadOS 26.5 and macOS Tahoe 26.5.
- CVE-2026-43725 — Apple WebKit sandbox boundary issue: a malicious website could process restricted web content outside the sandbox. Addressed with improved input validation. Credited on macOS Sonoma and macOS Sequoia.
- CVE-2026-33413 — etcd authorization bypass across multiple APIs (MemberList, Alarm, Lease, compaction). CVSS 8.8.
- CVE-2026-33343 — etcd nested transactions bypass RBAC entirely. CVSS 6.5.
- CVE-2026-31360 — Traefik SPIFFE trust-domain bypass: cert host overwrote expected host before comparison, enabling cross-trust-domain impersonation. MITRE-assigned; fix merged.
- CVE-2026-31361 — Traefik ACME private-key exposure:
%+vlogged full DER key on parse failure, a five-year unported regression. MITRE-assigned; fix merged. - CVE-2026-6994 — Envoy query-parameter injection via
header_mutation. Auth bypass and SQLi/XSS upstream. CVSS 6.3. - CVE-2026-47698 — vm2 sandbox breakout via stacked call indirection around dangerous host prototype-mutator checks, enabling arbitrary host command execution. CVSS 9.8; fixed in 3.11.6. GitHub advisory; credited as a reporter.
Other research
- WebKit / Apple Security Bounty — active submissions accepted. Disclosure pending.
- libvpx / libaom — codec library findings accepted. Disclosure pending.
Writeups
48 Hours on a SCADA Honeypot
WannaCry samples still propagating in 2026, Outlaw/mdrfckr botnet credential stuffing from Romania, Solana validator credential harvesting, automated Modbus/TCP scanning. Two days of captures from a SCADA-themed honeypot on Hetzner.
Wonder Ad Blocker — Reverse Engineering a Malicious Chrome Extension
A Chrome extension marketed as an ad blocker, with 500,000+ users, was operating as a distributed ad-intelligence scraping platform — injecting tracking scripts, harvesting browsing data, phoning home to command infrastructure.
Contact
- Twitter / X: @lukefr09
- GitHub: github.com/lukefr09
- Email: luke@linefeed.sh