Interests

  • Web Security
  • Browser Security
  • AI Agent Security

Education

2025.08 – present

M.S. in Computer Science and Engineering

Ulsan National Institute of Science and Technology, @UNIST WebSec Lab

Advisor: Seongil Wi

2021.03 – 2025.08

B.S. in Industrial Security & Police Science & Crime Investigation Software

Dongguk University, Korea

Publications

[1] BUIzz: Finding Policy Enforcement Bugs via Interaction Simulation on the Browser User Interface

Mingi Jung, Donggyu Kim, Mijung Kim, Seongil Wi

In Proceedings of the USENIX Security Symposium (USENIX Security), 2026 (Acceptance Rate: 11.96%)

AwardUSENIX Internet Defense Prize (Top 0.8%, 3/362) · funded by Meta · $25,000 Gift Award

AwardDistinguished Paper Award Runner-Up (Top 6%, 22/362)

[2] SandVenture: Escaping JavaScript Sandboxes with Objective-driven Input Generation

Mingi Jung, Hyeon Heo, Seongil Wi

In Proceedings of the IEEE European Symposium on Security and Privacy (IEEE EuroS&P), 2026 (Acceptance Rate: 17.83%)

Honors

USENIX Internet Defense Prize (Top 0.8%, 3/362) — $25,000 Gift Award, funded by Meta USENIX Security  ·  2026
Distinguished Paper Award Runner-Up (Top 6%, 22/362) USENIX Security  ·  2026
IBSM Award (Outstanding Graduate Student Award) UNIST  ·  2026.02.04

Security Bugs

CVE

GHSA-5gg3-f7j5-hfv4 Lightpanda (Lightpanda Browser) SameSite=Lax cookie bypass
GHSA-955g-h32v-mvrr Zauberzeug (NiceGUI) XSS via prop injection in ColorPicker.set_color()
CVE-2026-34514 aio-libs (aiohttp) HTTP header injection via CRLF
CVE-2026-21932 Oracle (Oracle Java SE) Unauthorized data modification via network access
CVE-2026-0877 Mozilla (Firefox Browser) DOM security mitigation bypass
CVE-2025-69235 Naver (Whale Browser) Same-Origin Policy bypass
CVE-2025-69234 Naver (Whale Browser) Iframe sandbox escape
CVE-2025-62585 Naver (Whale Browser) CSP bypass
CVE-2025-62584 Naver (Whale Browser) Same-Origin Policy bypass
CVE-2025-62583 Naver (Whale Browser) Iframe sandbox escape
CVE-2025-53791 Microsoft (Edge Browser) Security feature bypass
CVE-2025-53600 Naver (Whale Browser) Same-Origin Policy bypass
CVE-2025-48980 Brave Software (Brave Browser) SameSite cookie bypass
Discovered by our USENIX Security 2026 paper, BUIzz: Finding Policy Enforcement Bugs via Interaction Simulation on the Browser User Interface. In Brave Browser Desktop prior to 1.83.10 with the split view feature enabled, the “Open Link in Split View” context menu item did not respect the SameSite cookie attribute, so SameSite=Strict cookies were sent on a cross-site navigation triggered through this user interface path.
CVE-2025-32792 Endo (Secure ECMAScript) Lexical scope exposure in SES sandbox
Discovered via Strategy 5 of our IEEE EuroS&P 2026 paper, SandVenture: Escaping JavaScript Sandboxes with Objective-driven Input Generation. Web pages and extensions using ses and the Compartment API to evaluate third-party code in an isolated environment inadvertently expose const, let, and class bindings declared in the top-level scope of a <script> tag to the lexical scope of untrusted third-party code.

Acknowledgement

MSRC 2026 Bounty Technical Leaderboard Microsoft (Edge) · Rank #8
Mozilla Bug Bounty Hall of Fame Mozilla Foundation · 2026 Q1
NBB-2026-0007 Naver Corporation
NBB-2025-0211 Naver Corporation
NBB-2025-0209 Naver Corporation
KV-2025-186 Kakao Corporation
KV-2025-185 Kakao Corporation

Contact

Office Ulsan National Institute of Science and Technology, Ulsan