SSD Secure Disclosure logo
Brian showing SSD's quick handling process

Quick
handling

When a vulnerability is found, it needs to get into the right hands quickly. We offer a fast and straightforward approach to disclosing your research and the quickest submission process out there.

Brain showing SSD's generous rewards

Generous
rewards

We believe researchers' efforts should be compensated with the highest payouts. If a vendor doesn’t accept disclosures, we will still be interested in acquiring the vulnerability and reporting it.

Brian showing SSD's discretion standard

Done
discreetly

Many of our researchers utilize our maximum privacy protection and choose to stay anonymous when submitting their findings. We take the privacy of our researchers very seriously and will never disclose any information to third parties (Customers included).

SSD provides the knowledge, experience and tools needed to find and disclose vulnerabilities and advanced attack vectors.

What We Do

The researcher sends us a brief description of the vulnerability for review

the researcher submits the full discovery details and exploits. our team tests and verifies the findings.

SSD signs a detailed contract – focused on protecting your research.

the researcher gets the full payout within a week

the vulnerability is disclosed and published. Full credit is given to the researcher.

Our targets of interest include a vast scale of software and hardware and is being updated constantly. We are always on the lookout for:

operating systems

Windows (RCE and PE)
Linux bugs
MacOS bugs

mobile

iOS PE
iOS SBX
Android
iOS baseband

web
browsers

Chrome (RCE or SBX)
Safari
Firefox (RCE)

UNISOC T612 LPE

Summary UNISOC (Shanghai) Technologies Co., Ltd. is a top-three global fabless semiconductor company headquartered in Shanghai, specializing in 2G/3G/4G/5G mobile communication, IoT, and smart device chipsets. Formerly Spreadtrum, it serves major brands like Honor, realme,

Linux Bridge STP Timer Use-After-Free

Summary A use-after-free vulnerability in the Linux kernel bridge (net/bridge) Spanning Tree Protocol (STP) implementation. A bridge that is administratively down while kernel STP is enabled, together with a port driven into the LEARNING state,

vBulletin Runtime Template runMaths Preauth RCE

Summary A vulnerability in vBulletin has been identified, the vulnerability allows an unauthenticated user to cause the vBulletin to execute arbitrary code (PHP) on the remote server. Vendor Response The vendor has issued a fix

?

Skip to content