Skip to content
View pavanchow's full-sized avatar
:electron:
:electron:

Block or report pavanchow

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
pavanchow/README.md
Pavan Nallamothu
typing

CVEsAppleCISANSA

whoami

Security researcher and penetration tester. I find and responsibly disclose vulnerabilities in commercial and open-source software. M.S. Cybersecurity, and CTF web-challenge author at the ISC2 New Jersey Chapter.

  • 🛡️ 12 published CVEs (MITRE), credited by Apple, CISA, and the NSA
  • 🎯 Bug bounty on HackerOne, Bugcrowd, Google VRP, Apple Security Bounty, and Meta
  • 🔎 Focus areas: SSRF, broken access control, IDOR, path traversal, source-code auditing
  • 📍 Jersey City, NJ

🧾 Selected CVEs

CVETargetClassSeverity
CVE-2026-43763Apple macOS (ATS)Sandbox file-read🟠 Medium
CVE-2026-63013NSA skills-servicePrivilege escalation🔴 High 8.8
CVE-2026-63014NSA skills-serviceCross-project IDOR🟠 Medium
CVE-2026-63177CISA MalcolmRBAC bypass🔴 High
CVE-2026-63134 / 63133CISA MalcolmPath traversal, DoS🟠 Medium
CVE-2026-33234AutoGPTSSRF via SMTP🟠 Medium
CVE-2026-50023yt-dlpDangerous file creation🔴 High 8.3
CVE-2026-40585 to 40588BlueprintUEAccount-takeover chain🔴 High

🛠️ Open-source builds

Systems tools written from scratch, each its own repo with a live page. Full set at pavanchow.github.io.

BuildWhat it is
OracleA query language whose result is an attack path across identity and network graphs
Lint-OwlA static analyzer that returns the data-flow path from source to sink
UnweaveAn EVM bytecode disassembler that reconstructs intent and flags dangerous opcodes
CipherlockFrom-scratch ChaCha20-Poly1305 AEAD, proven against the RFC 8439 vectors
TimelaceA content-addressed version-control core, the git idea made readable
TrailheadA full-text search engine with an inverted index and TF-IDF ranking

🧰 Toolbox

PythonBashGoBurp SuiteWiresharkLinuxAWSDockerKubernetes

🌐 Connect

PortfolioLinkedInEmail

Pinned Loading

  1. crawlyncrawlynPublic

    Forked from iamcryptoki/crawlyn

    Experimental crawler to grab data from websites.

    Python

  2. mit-licensemit-licensePublic

    Forked from remy/mit-license

    Hosted MIT License with details controlled through this repo

    CSS

  3. pavanchow.github.iopavanchow.github.ioPublic

    GitHub Pages

    HTML

  4. sherlocksherlockPublic

    Forked from sherlock-project/sherlock

    🔎 Find usernames across social networks

    Python