Yesterday we dropped our latest write-up on a previous Chrome 0-day.
Today we got assigned yet another Chrome 0-day: CVE-2026-7899 — along with a $55,000 bounty from Google
If you haven’t read yesterday’s blog yet, go check it out down below. It’s a fun one.
Now it’s time for us to prepare the next few write-ups. A Chrome RCE and a Linux kernel local privilege escalation. Stay tuned 👀
https://t.co/Xi5Z9NDIDW
Our code auditing agent with “inferior” model discovered 300+ bugs in 3 days under $20k cost. 25 were confirmed exploitable zero-days. We already built 6 browser exploits across 6 different 0-days and 3 Google COS kernel exploits, with 21 more exploitable cases in the pipeline:
Congrats to us for achieving #1 in the 2025 CTFtime world rankings 🏆🌍!
It’s been an absolutely thrilling year, starting out in the lead, then slipping after a tough loss to 2nd place, and finally fighting our way back to 1st by the end of the year 📈.