$ whoami

Mohammad Kaif

Security Researcher & Bug Hunter

Android API Web Cloud

I break things responsibly — hunting vulnerabilities across web apps, Android apps and APIs. Awarded a $15,000 bounty by Apple, ranked #1 researcher at Tecno and OPPO, and listed on Apple's Hall of Fame five times.

01. About

I'm a security researcher and bug hunter passionate about finding vulnerabilities in web applications, Android apps and APIs. My work spans account takeovers, CSRF, IDOR, JWT flaws, API abuse and mobile reverse engineering.

I've worked with the security teams of Apple, Tecno, OPPO and programs on HackerOne — earning a $15,000 bounty from Apple for an App Store account takeover, ranking as the #1 researcher on multiple leaderboards, and being listed on Apple's Hall of Fame five times.

I'm currently pursuing a B.Tech in Computer Science & Engineering at Dr. A. P. J. Abdul Kalam Technical University, Lucknow (2022–2026). I believe in responsible disclosure and in giving back through detailed public writeups.

# profile.yaml
name:     Mohammad Kaif
handle:   kaif0x01
role:     Security Researcher
focus:    [web, android, api]
edu:      B.Tech CSE (AKTU)
based_in: India
status:   hunting…
$25K+bounties from Apple
Apple Hall of Fame
74+accepted reports @ Tecno
#1researcher @ Tecno & OPPO

02. Experience

Independent Security Researcher · Apple

2025 – Present

Apple Security Bounty Program

  • Reported a critical Account Takeover via the App Store with a working exploit & PoC; after Apple's same-day fix I found a unique bypass — earning a $15,000 bounty.
  • Disclosed 2 unique CSRFs in the App Store and iTunes (Music) via the itmss:// scheme, affecting users' Apple Account billing information — $5,000 each.
  • Exploited an iTunes (Music) macOS flaw allowing any site to load into the internal webview and reach the JS bridge, exposing account data (dsId, email, guid, name, Machine ID).

Independent Security Researcher · Tecno Mobile

2021 – 2025

Tecno Security Response Center

  • Researched business-critical apps — TECNO SPOT (500M+ installs), Boomplay (100M+), Tecno ID and Tecno Cloud.
  • Reverse-engineered Android apps with JADX & apktool and exploited API flaws with Burp — finding PII leakage, account takeovers and IDORs in core functionality.
  • Disclosed 120 vulnerabilities (74 accepted): 14 Critical, 29 High, 23 Medium, 8 Low. Ranked #1 researcher in 2024, 2023 & 2021.

Independent Security Researcher · OPPO

2019 – 2021

OPPO Security Response Center

  • Performed security research across OPPO's web and mobile assets, including e-commerce and community platforms — finding Stored XSS, IDOR and CORS misconfiguration issues.
  • In a fintech app, found source-code leakage via an insecure Docker Registry API and an account takeover by forging JWT tokens.
  • Helped secure internal source code exposed through a misconfigured container registry. Ranked #1 researcher in 2020 & 2021.

Bug Bounty Hunter · HackerOne

Ongoing

@kaif0x01 · 607 reputation · 94th percentile

  • Reported valid vulnerabilities to programs including Xiaomi, Zomato (Eternal) and private programs.
  • Stats: 7.00 signal, 24.69 impact, 94th percentile, 607 reputation.

03. Highlights

🍎

Apple Hall of Fame

Earned a $15,000 bounty for an App Store account takeover plus 2× $5,000 for CSRFs — and listed on Apple's Hall of Fame 5 times (2023–2026).

hall of fame →
🎵

iOS 26.4 Security Credit

Acknowledged by Apple in the security content of iOS 26.4 and iPadOS 26.4 for reporting a vulnerability in the Music app, fixed in the update.

apple advisory →
🏆

#1 Ranked Researcher

Top-ranked researcher at the Tecno Security Response Center (2024, 2023, 2021) and OPPO SRC (2021, 2020) — with 74+ accepted reports at Tecno alone.

read writeups →

04. Focus Areas

web_security

  • CSRF & auth flaws
  • XSS · IDOR · CORS
  • JWT & business logic

android_security

  • Reverse engineering
  • JADX & apktool
  • Deeplink & webview abuse

api_security

  • Account takeovers
  • BOLA / broken auth
  • PII & config leakage

tooling

  • Python · JavaScript · Bash
  • Burp Suite · Wireshark
  • Git · Linux · Docker

05. Writeups

06. Resume

Want the full picture?

Grab a copy of my resume for the complete rundown of experience, certifications and research work.

Download Resume (PDF)

07. Get In Touch

Have a security concern, a collaboration idea, or just want to talk bugs? My inbox is always open.

Say Hello