CVE-2026-43816
An out-of-bounds write in the kernel, fixed in iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, watchOS 26.6, tvOS 26.6 and visionOS 26.6.
Muneeb Amin Bhat is among the researchers Apple credits.
Security testing
Hands-on tests. Proof you can reproduce.
All security testingHow we workWhat happens after the first call.See the processBuild
We break software for a living. This is what we build.
All build servicesProof of workOur own apps, built the same way.See themMuneeb Amin Bhat’s research, from an Oracle CVE in 2022 to the company he opened in August 2026.
Deep in the stack or out on the open web, the job is the same: find what breaks, prove it, report it.
The core of the operating system. A bug there reaches everything above it.
Business suites that hold a company’s money, staff and data.
Code that runs before the operating system, where trust starts.
Servers, APIs and the cloud behind them.
Banks, exchanges and payments, where a bug touches real money.
Chains, bridges and the contracts on them, where the code is the vault.
New systems, and new ways for them to fail.
Code anyone can read, run by people on their own servers.
The apps people open every day.
Starts hunting on bug bounty and disclosure programs.
Oracle E-Business Suite. CVSS 3.1 base score 7.5.
Sourcefor CVE-2022-21500, credited by Oracle (opens in a new tab)Listed for reports on Apple’s web servers.
Sourcefor Apple Web Server Security Acknowledgements (opens in a new tab)Daily Excelsior, Kashmir Life and Greater Kashmir cover the Apple listing.
Sourcefor First press, at home (opens in a new tab)WION runs the NASA story online and on Gravitas. ANI, DNA India and ABP Live follow.
Sourcefor WION, on prime time (opens in a new tab)His reports to Apple, NASA and Google, online and in print.
Sourcefor The Hindu BusinessLine feature (opens in a new tab)Profiled in “Guardians of the Grid”.
Sourcefor NITI Aayog Frontier Tech Hub (opens in a new tab)Accepted and rewarded in the Trusted Firmware scope.
A kernel out-of-bounds write, fixed in iOS 26.6 and macOS Tahoe 26.6.
Sourcefor CVE-2026-43816, credited by Apple (opens in a new tab)MSME registered, Udyam UDYAM-JK-11-0024606.
The count as of September 2026, since 2022.
An out-of-bounds write in the kernel, fixed in iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, watchOS 26.6, tvOS 26.6 and visionOS 26.6.
Muneeb Amin Bhat is among the researchers Apple credits.
CVSS 3.1 base score 7.5, from Oracle’s own Security Alert. The alert credits him as “Bhat Muneeb”.
Oracle Security Alert(opens in a new tab)In 2026 Arm’s bug bounty program accepted and rewarded his findings in its Trusted Firmware scope.
Firmware and IoT testingWeb Server Security AcknowledgementsAcknowledgement
August 2023
Vulnerability Disclosure Program Hall of FameHall of fame
2024
Hall of Fame
Hall of Fame
Bug bounty programAcknowledgement
Security programAcknowledgement
Bug bounty programAcknowledgement
Apple
In August 2023 Apple listed me in its Web Server Security Acknowledgements. Back home, Daily Excelsior reported the find as an iCloud issue that exposed user data. It was my first time in the papers.
NASA
In 2024 NASA added me to its Vulnerability Disclosure Program Hall of Fame. ABP Live reported it was for data breach vulnerabilities. WION ran the story on prime time, ANI put it on video, and outlets across India followed.
Arm and Apple
In 2026 Arm’s bug bounty program accepted and rewarded my findings in Trusted Firmware. In July Apple credited me for CVE-2026-43816, a kernel out-of-bounds write. A month later I opened Vulnara.
I work from Kulgam, in south Kashmir. My reports land with security teams in the US, the UK and Germany.
KulgamtoUnited States
Apple, Google, NASA, NVIDIA, USAA, Indeed, Kraken, Vercel, Lightspark, Anthropic, Oracle, McDonald’s, Pinterest, Zendesk, Asana and Fireblocks
KulgamtoUnited Kingdom
Arm
KulgamtoGermany
SimScale and Nextcloud
KulgamtoIndia
NITI Aayog
In 2025 the Government of India’s policy think tank put him in a Frontier Tech Hub story on young Indians in cyber security.
Guardians of the Grid: 7 Young Indians Fortifying Our Cyber Frontiers
When NASA listed me, the story made it to TV.
Send the scope and your deadline, and we’ll set up a call.
Web and API penetration testingWeb apps and APIs, tested by hand.
Smart contract auditsSolidity, read line by line and fuzzed.
Mobile and desktop app securityAndroid, iOS, macOS and Windows apps.
Network and cloud securityNetworks, plus AWS, GCP and Azure.
Firmware and IoT securityFirmware, device services, updates.
Open-source securityDependencies, pipelines, disclosure.