Wongi Lee

Undergraduate student in Computer Science and Engineering.

Work Experience

Theori

Researcher

Jun 2022 -

Worked on vulnerability research, exploit development, and security engineering projects, progressing from internship work to independent research ownership.

Researcher

Aug 2025 -

Owned research tasks from idea validation through exploit development, documentation, and public-facing presentation or disclosure work.

Junior Researcher

Jan 2024 - Jul 2025

Contributed to vulnerability research and exploit tooling with a focus on kernel, browser, and systems security topics.

Intern Researcher

Jun 2022 - Aug 2022, Mar 2023 - Dec 2023

Supported offensive security research and implementation work across internal projects, training material, and vulnerability analysis tasks.

Presentations

POC Conference 2025

Presented a race-condition exploitation workflow, following the path from a small bug idea to a practical pwnable impact.

HEXACON 2024

Presented a Linux kernel exploitation technique based on cross-CPU allocation behavior in preempt-disabled execution paths.

Experience

Chromium and Third-Party Contributions

V8, Blink, FFmpeg, Sanitizer API

2026 -

Contributed vulnerability research across Chromium and related components, including CVE-2026-8539 and CVE-2026-7335.

.HACK Conference

Organizer

2025 - 2026

Organized CTF and booth operations, preparing event content and on-site technical programs.

Linux Kernel Contributions

2024 -

Contributed Linux kernel vulnerability work and disclosures, including CVE-2024-41010 and CVE-2024-50264.

kernelCTF Submissions

2024 -

Submitted multiple kernelCTF exploits and writeups, including exp183, exp184, exp196, exp197, exp237, and exp522.

Cold Fusion

CTF Team Lead

2024 -

Led CTF team operations and built tooling for competition workflows.

DEF CON Exploit Manager

Designed and developed an exploit, packet, and patch management system for CTF operations and competition-time coordination.

Lectures and Content

Systems Security Lectures

Authored practical security lecture material covering Linux fundamentals, glibc exploitation, Linux kernel internals, V8, and Windows internals.

Covered files, directories, processes, environment variables, file descriptors, package management, networking, and editor workflows.

Covered libc GOT overwrite, FSOP, exit handlers, TLS destructor lists, safe linking, and related exploitation techniques.

Covered kernel exploitation primitives, allocator internals, msg_msg, pipe_buffer, and simple_xattr attack surfaces.

Covered V8 object and heap structure, garbage collection, optimization behavior, and exploitation techniques.

Covered PE files, SEH, CFG, NT heap, segmented heap, and Windows exploitation fundamentals.

CTF Challenge Authoring

Designed and wrote CTF challenges for security education and competition practice.

Awards

2026

DEF CON CTF Final · Cold Fusion

Finalist

2025

Pwnie Awards

Best Priv Esc

2025

Pwn2Own

RHEL

2025

DEF CON CTF Final · Cold Fusion

10th

2025

HITCON CTF · CTF Demon Hunters

4th

2024

DEF CON CTF Final · Cold Fusion

9th

2024

HITCON CTF Final · Cold Fusion

6th

2024

ICPC Seoul Regional Finals · ConForza

2024

UCPC Final

2023

HITCON CTF Final · Program Teolmochi

4th

2023

Codegate CTF Finals

3rd

2023

ICPC Seoul Regional Finals · BalloonBreakers

2023

PPC

3rd

2022

Codegate CTF Finals

5th

2022

ICPC Seoul Regional Finals · CRYPKING

2021

PPC · SOTA

2nd