Lupus Nova

Security research and reverse engineering

Find out more

A focused set of skills at your service

I am an independent vulnerability researcher based in the French Alps. I work on vulnerability research, reverse engineering and software development, exclusively on Apple platforms.

Explore my services

A few examples of engagements

iOS & macOS application audit

I run black-box analysis on iOS applications. This approach surfaces concrete, realistic attack scenarios, and I then support you through to remediation of every issue found.


SDK and native component audit

An embedded third-party SDK inherits every privilege your application holds, with no access to its source. I analyse it to establish what it actually collects and what it exposes.


Third-party application assessment

Before an application is deployed across an iOS fleet, I establish what it really collects, where the data goes and which permissions it claims — a reasoned opinion a CISO can act on.


Apple vulnerability research

I take part in the Apple Security Bug Bounty by reporting and helping them to fix the vulnerabilities I find across iOS, macOS, tvOS, watchOS and visionOS. See the CVEs identified.


Client references

Fintech SaaS vendor — black-box audit

Analysis with no access to source code or documentation. A bypass of the cryptography implemented by the application has been found, demonstrated with a proof of concept and subsequently fixed.

E-commerce platform — white-box audit

Security review carried out with access to the source code. Two vulnerabilities identified and qualified, fixed together with the development team ahead of release.

SOC Hockey sur Glace — mobile app development

Design and development of the club's mobile application, from requirements definition through to App Store release.

By the numbers

2024

Started in


Lupus Nova start date

10

Years of experience


Lupus Nova experience

Acknowledged by Apple Product Security

Thirty vulnerabilities reported to Apple since 2024, twenty-four of which have been fixed and assigned a CVE identifier and credited by name in the official security advisories, across macOS, iOS, watchOS and visionOS.

See the CVE list
Responsible disclosure

Responsible disclosure

I work together with the vendors to get every vulnerability fixed. Once the patch has been shipped and with the agreement of all parties, an article may be written to inform the public.

See the CVEs Read the blog

Ready to take the plunge?

Get in touch
Contact Lupus Nova