Interests
- Web Security
- Browser Security
- AI Agent Security
Education
2025.08 – present
M.S. in Computer Science and Engineering
Ulsan National Institute of Science and Technology, @UNIST WebSec Lab
Advisor: Seongil Wi
2021.03 – 2025.08
B.S. in Industrial Security & Police Science & Crime Investigation Software
Publications
[1] BUIzz: Finding Policy Enforcement Bugs via Interaction Simulation on the Browser User Interface
In Proceedings of the USENIX Security Symposium (USENIX Security), 2026 (Acceptance Rate: 11.96%)
AwardUSENIX Internet Defense Prize (Top 0.8%, 3/362) · funded by Meta · $25,000 Gift Award
AwardDistinguished Paper Award Runner-Up (Top 6%, 22/362)
Honors
USENIX Internet Defense Prize (Top 0.8%, 3/362) — $25,000 Gift Award, funded by Meta
Distinguished Paper Award Runner-Up (Top 6%, 22/362)
IBSM Award (Outstanding Graduate Student Award)
Security Bugs
CVE
Discovered by our USENIX Security 2026 paper, BUIzz: Finding Policy Enforcement Bugs via Interaction Simulation on the Browser User Interface.
In Brave Browser Desktop prior to 1.83.10 with the split view feature
enabled, the “Open Link in Split View” context menu item did not respect the
SameSite cookie attribute, so SameSite=Strict cookies
were sent on a cross-site navigation triggered through this user
interface path.
Discovered via Strategy 5 of our IEEE EuroS&P 2026 paper, SandVenture: Escaping JavaScript Sandboxes with Objective-driven Input Generation.
Web pages and extensions using ses and the Compartment API to evaluate
third-party code in an isolated environment inadvertently expose
const, let, and class bindings
declared in the top-level scope of a <script> tag to the
lexical scope of untrusted third-party code.
Acknowledgement
Contact
Email
wjdaslrl4475@unist.ac.kr
Office
Ulsan National Institute of Science and Technology, Ulsan
GitHub
github.com/mingijunggrape