Log inSign up
@[email protected]
1,210 posts
@SecurityMB

@[email protected]

@SecurityMB
Improving the world’s security at Google. Opinions are mine.
Zurich, Switzerland
bentkowski.info
Joined September 2014
284
Following
11.1K
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • Pinned
    @SecurityMB
    @[email protected]
    @SecurityMB
    Jun 15, 2020
    Finally, my research is published. It has everything you might wish for in browser security: universal XSS, mutation XSS, CSS data exfiltration, and others. Check this out! In a few days, we'll also release a 30-minute presentation about this topic.
    @securitum_com
    Securitum
    @securitum_com
    Jun 15, 2020
    We are publishing the research of Copy&Paste issues in browsers by @SecurityMB. Over $30k in bounties for bugs in Chromium, Firefox, Safari, Google Docs, Gmail, TinyMCE, CKEditor, and others. Includes also 0-day in Froala. research.securitum.com/the-curious-ca…
    9
  • @SecurityMB
    @[email protected]
    @SecurityMB
    Jun 15
    This is a really awesome summary of how to approach bypassing HTML sanitizers, I highly recommend to check this out!
    @kinugawamasato
    Masato Kinugawa
    @kinugawamasato
    Jun 12
    DOMPurifyバイパスの歴史をまとめたページ。HTMLサニタイザーバイパスのノウハウがぎっしり詰まってる。 特に今年に入ってから発見された<selectedcontent>のバイパスは驚いた github.com/cure53/DOMPuri…
  • @SecurityMB
    @[email protected]
    @SecurityMB
    May 18
    Anyone I know interested in joining the Google Security Team in Zurich? Let me know, I can give a referral :D Here's the job posting: google.com/about/careers/…
    12
  • @SecurityMB
    @[email protected]
    @SecurityMB
    Mar 6
    That must be the worst captcha I’ve ever seen.
    Image
  • @SecurityMB
    @[email protected]
    @SecurityMB
    Jan 24
    That was a nice bug, thanks for the shoutout!
    @intigriti
    Intigriti
    @intigriti
    Jan 23
    Replying to @intigriti
    2️⃣ XSS in GMail's AMP4Email via DOM Clobbering Michał Bentkowski (@SecurityMB) exploited DOM clobbering to achieve XSS in Gmail's AMP4Email feature. Found that AMP4Email allowed id attributes, which could be leveraged to overwrite JavaScript variables and bypass Google's strict
    1
Advertisement
Advertisement