I am an independent vulnerability researcher based in the French Alps. I work on vulnerability research, reverse engineering and software development, exclusively on Apple platforms.
Explore my servicesI run black-box analysis on iOS applications. This approach surfaces concrete, realistic attack scenarios, and I then support you through to remediation of every issue found.
An embedded third-party SDK inherits every privilege your application holds, with no access to its source. I analyse it to establish what it actually collects and what it exposes.
Before an application is deployed across an iOS fleet, I establish what it really collects, where the data goes and which permissions it claims — a reasoned opinion a CISO can act on.
I take part in the Apple Security Bug Bounty by reporting and helping them to fix the vulnerabilities I find across iOS, macOS, tvOS, watchOS and visionOS. See the CVEs identified.
Analysis with no access to source code or documentation. A bypass of the cryptography implemented by the application has been found, demonstrated with a proof of concept and subsequently fixed.
Security review carried out with access to the source code. Two vulnerabilities identified and qualified, fixed together with the development team ahead of release.
Design and development of the club's mobile application, from requirements definition through to App Store release.
Thirty vulnerabilities reported to Apple since 2024, twenty-four of which have been fixed and assigned a CVE identifier and credited by name in the official security advisories, across macOS, iOS, watchOS and visionOS.
See the CVE listI work together with the vendors to get every vulnerability fixed. Once the patch has been shipped and with the agreement of all parties, an article may be written to inform the public.
See the CVEs Read the blog