Security researcher / India
Assume nothing.Trust no input.
I research vulnerabilities in mobile apps, web applications, cloud services, and smart contracts. This site is where I publish the work.
Recent write-ups
Bugs I found and how they worked.
Published
When WebView bites back
An exported Android activity loaded attacker-controlled content in a WebView and allowed JavaScript execution.
- Vector
- Exported activity
- Outcome
- JavaScript execution
Published
The function that could mint forever
A missing authorization check allowed the contract to mint tokens without a supply limit.
- Vector
- Missing authorization
- Outcome
- Unlimited minting
Published
How a news app leaked OAuth codes
A conflicting Android deep link let another app receive an OAuth authorization code.
- Vector
- Deep-link collision
- Outcome
- Code interception
Published
SQLi: finding to exploitation
How I confirmed a SQL injection, demonstrated database impact, and reported it responsibly.
- Vector
- Unsafe input
- Outcome
- Database access
Assigned vulnerabilities
Assigned CVEs.
Security acknowledgements
Hall of fame and thanks received.
Organizations that acknowledged or credited my vulnerability reports.

.svg.png)
.svg.png)
Books and notes
What I’m reading.
Five books I keep returning to, and the idea each one left behind.
The Brothers Karamazov
My notes on faith, doubt, responsibility, and how people justify their choices.
Explanations that change what is possible.
Decisions, incentives, and long horizons.
Attention, restraint, and self-command.
Power, dignity, and the cost of survival.