Skip to content
View GAP-dev's full-sized avatar
👾
Focusing
👾
Focusing

Organizations

@Apple-Reversing-Tools

Block or report GAP-dev

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
GAP-dev/README.md

👋 Who4mI

이동하 (DongHa Lee)

🎂 2004.02.18 (23 y.o)

📧 p@sswd.pw

🌐 dongha.xyz

🎮 Discord : lee_dongha


🧑‍💻 I'm a Security Researcher in KR

Hi, I’m DongHa — a passionate vulnerability researcher, CTF challenge author, and bug hunter with a special interest in fuzzing and AI for security. I’ve published CVEs and regularly contribute to security conferences, academic research, and open-source projects.


✨ Masterpiece

🔎 Dive into what I’ve done during a magical month:
👉 December 2022 Activity


🔒 Technical Skills

  • Vuln Research: pwnable, web hacking, reversing, AI, fuzzing, crypto (PQC)
  • Languages: C, C++, Python, Rust, x86 ASM, Node.js, CUDA
  • Systems: Embedded dev, Docker, Linux Kernel

📌 Published CVEs

  • CVE-2023-43646 | CVSS 7.5 / CWE-400, CWE-1333 / ReDoS
  • CVE-2023-45827 | CVSS 9.8 / CWE-1321 / PP
  • CVE-2023-50245 | CVSS 9.8 / CWE-120 / Buffer Copy without Checking Size of Input
  • CVE-2024-23339 | CVSS 6.5 / CWE-1321 / PP
  • CVE-2024-22526 | CVSS 5.5 / CWE-120 / Buffer Copy without Checking Size of Input
  • CVE-2024-27088 | CVSS 5.5 / CWE-400, CWE-1333 / es5-ext(ECMAScript 5 extensions)
  • CVE-2024-20746 | CVSS 7.8 / CWE-787 / Adobe Premiere Pro Out-of-bounds Write
  • CVE-2024-42358 | CVSS 5.5 / CWE-835 / Loop with Unreachable Exit Condition ( DoS )
  • KVE-2024-0820 | find the gap private bug bounty
  • KVE-2024-0821 | find the gap private bug bounty
  • KVE-2024-0454 | kisa knvd report
  • CVE-2024-45870 | CVSS 6.5 / CWE-284 / Improper Access Control
  • CVE-2024-45871 | CVSS 6.3 / CWE-20 / Improper Input Validation
  • CVE-2024-45872 | CVSS 6.3 / CWE-122 / Heap-based Buffer Overflow
  • CVE-2024-44913 | CVSS 5.5 / CWE-284 / Improper Access Control
  • CVE-2024-44914 | CVSS 5.5 / CWE-284 / Improper Access Control
  • CVE-2024-44915 | CVSS 5.5 / CWE-284 / Improper Access Control
  • CVE-2025-4605 | CVSS 5.5 / CWE-789 / Autodesk MAYA 2025 memory corruption
  • CVE-2025-24184 | Apple iOS 18.3, visionOS 2.3, watchOS 11.3, tvOS 18.3, macOS Sequoia 15.3 CoreMedia Playback
  • CVE-2025-53015 | CVSS 7.5 / CWE-835 / XMP Profile bug
  • CVE-2025-43338 | Apple macOS/IOS/etc Tahoe 26.0 ImageIO [+1000usd]
  • CVE-2025-43372 | Apple macOS/IOS/etc Tahoe 26.0 CoreMedia [+1000usd]
  • CVE-2025-43287 | Apple macOS/IOS/etc Tahoe 26.0 ImageIO
  • CVE-2025-10500 | Chromium gpu bug [+15000usd]
  • CVE-2025-43401 | Apple macOS/IOS/etc Tahoe 26.1 CoreAnimation
  • CVE-2025-43511 | Apple WebKit GPU bug [+1000usd]
  • CVE-2025-23339 | Nvidia CUDA Toolkit
  • CVE-2026-20695 | ZDI-CAN-28499, Apple XNU Kernel Tahoe 26.3
  • CVE-2026-28868 | Apple XNU Kernel Tahoe 26.3 [+1000usd]
  • CVE-2026-28817 | Apple macOS/IOS/etc Tahoe 26.3 Print [+20000usd]
  • CVE-2025-54372 | pendding

and more... Discontinued due to AI

  • CVE-2026-85062 | !!My First CVE in 2023!! ReDoS in Colord NPM module

🗣️ Presentations & Lectures

  • Fuzzing & Symbolic Execution - CCA National Information Security Club Association Seminar (2025.02)
  • Metaverse Fuzzing으로 0-day 찾기 - KUCIS 영남권 세미나 (2024.10)
  • KISA Academy 버그 헌팅 마스터 과정 메인 강사 (2024.06)
  • Address Sanitizer and Out of Bound vulnerabilities - CCA Seminar (2024.03)
  • 동아리 모의 해킹 스터디 강의(2024)
  • 네트워크 보안 수업 실습 조교 (2024)
  • ReDoS 취약점 탐지 도구의 동향 분석 및 개선을 통한 취약점 분석 연구 발표 – 한국정보보호학회 (2023.11)
  • ReDoS 자동화 탐지 방법론 – KUCIS 서경강 세미나 (2023.09)

📝 Papers

  • 문서화되지 않은 macOS 인터페이스 식별을 통한 퍼블릭 프레임워크-XPC 서비스 의존성 그래프 생성 및 공격 표면 분석 | (KCI 저널)
  • 하이브리드 퍼징 연구 동향 및 기술적 챌린지 분석 | 한국정보보호학회
  • 정적 분석 및 동적 분석을 통한 안드로이드 퍼징 하네스 생성 | 한국정보보호학회
  • LLM 기반 소프트웨어 취약점 분석 연구 동향 및 기술적 챌린지 분석 | 한국정보보호학회
  • XPC 및 IOKit 기반 macOS 공격 표면 식별 자동화* | 한국정보보호학회
  • Towards Automated Vulnerability Analysis in ARM-based Virtualization* | KTCCS(KCI 저널)
  • macOS 커널 디버깅을 위한 심볼 이식 기법 연구 | 한국정보처리학회
  • 코퍼스 전이를 통한 상용 소프트웨어에 대한 바이너리 전용 퍼징 성능 향상* | 한국정보보호학회
  • ReDoS 취약점탐지 도구의 동향 분석 및 개선을 통한 취약점 분석 연구* | 한국정보보호학회
  • 프로토타입 오염 패턴 조사를 통한 Node.js 패키지 취약점 분석 연구 | 한국정보보호학회

🚀 Projects

  • Finding Vulnerabilities in Silicon macOS Virtualization
  • AFL++ opensource contribute
  • LKL gpu kernel driver fuzzing project (2024)
  • Hspace knights 활동 (2024)
  • ReBoB NodeBOB 팀 (2023)
  • CTF 출제 및 운영
  • 스마트교통 서비스 IoT 장치 취약점 분석 과제 수행
  • 기업 대상 모의 침투/컨설팅
  • R&D 과제 다수 진행

🏆 Awards

  • DEFCON 34 FINAL 7th place (2026.08)
  • SekaiCTF 2026 7th place (2026.06)
  • DEFCON 34 CTF Qualifier 6th place (2026.05)
  • TJCTF 2026 1st place (2026.05)
  • CODEGATE 2026 Qualifier CTF general 4th place (2026.03)
  • 한국정보보호학회 우수 논문상 (2025.11)
  • 도로교통안전공단 TS 모의해킹 경진대회 4th place (2025.11)
  • 우리은행 제5회 우리콘 모의해킹 경진대회 1st place (2025.09)
  • 제 2 회 와글와글 해커톤 (1st place) (2024.02)
  • 가천대학교 가천인재상 (2023.11)
  • 한국정보보호학회 우수 논문상 (2023.11)
  • 정보보호 정책제안 공모전 (본선진출) (2023.10)
  • 제 1 회 와글와글 해커톤 (3rd place) (2023.09)

🎓 Education

  • Best of the Best 14기 취약점분석
  • 가천대학교 정보보호학과 (2023년 ~ )

💼 Experience

  • suspended (2026년 6월 ~ 현재)
  • SSA LAB – 학부 연구생 (2025년 1월 ~ 2026년 5월)
  • engineer - private

🌐 Contact Me


Pinned Loading

  1. googleprojectzero/p0tools googleprojectzero/p0tools Public

    Project Zero Docs and Tools

    C++ 854 133

  2. AFLplusplus/AFLplusplus AFLplusplus/AFLplusplus Public

    The fuzzer afl++ is afl with community patches, qemu 5.1 upgrade, collision-free coverage, enhanced laf-intel & redqueen, AFLfast++ power schedules, MOpt mutators, unicorn_mode, and a lot more!

    C 6.8k 1.3k

  3. AFLplusplus/LibAFL AFLplusplus/LibAFL Public

    Advanced Fuzzing Library - Slot your Fuzzer together in Rust! Scales across cores and machines. For Windows, Android, MacOS, Linux, no_std, ...

    Rust 2.6k 480

  4. CVE-2024-22526 ZeroPointer DongHa Lee CVE-2024-22526 ZeroPointer DongHa Lee
    1
    
                  
    2
    bandisoft bandiview v7.0 is vulnerable to Buffer Overflow via exr image
    3
    file.
    4
    
                  
    5
    ------------------------------------------