Alex Chapman
banner
ajxchapman.bsky.social
Alex Chapman
@ajxchapman.bsky.social
Full Time #BugBounty Vulnerability Researcher

https://blog.ajxchapman.com
There is something quite depressing about many of the advertised agentic AI use cases being posting "viral" content to social media. It stinks of one person assuming their time is inherently worth more than everyone else.
August 8, 2025 at 3:36 PM
I presented my magnum opus in 2014 and have been in steady decline ever since.
July 21, 2025 at 4:48 PM
I love it when I answer my own questions
June 30, 2025 at 3:23 PM
Following other's lead, I put together an XSS challenge to solve a somewhat tricky injection I'd come across. In producing the challenge I came up with my solution (so in that way I guess it served it's purpose) but interested in how other's would approach it 🤔

blog.ajxchapman.com/xss/challeng...
March 10, 2025 at 4:19 PM
This is possibly the most out of the box (ha!) Chrome sandbox escape technique I've ever heard of 🤯

"Compromised renderer can control your mouse and escape sbx"
issues.chromium.org/issues/37085...
January 30, 2025 at 6:56 PM
It's some version of this, just with more and more AI companies lining up at the bottom 😆
January 29, 2025 at 3:51 PM
I don't like quoting from the bad site, but I have Thoughts. The primary being, if you cannot afford to host an LHE, don't host an LHE 🤦‍♂️

It's expensive to get a large group of experienced and proven #BugBounty hackers to spend weeks solely focused on a defined scope, who would have thought?
January 24, 2025 at 8:56 AM
I'm not convinced, see this graph of the amount of money I made in Poland last year... admittedly I didn't go to Poland last year, but my point stands
January 17, 2025 at 10:40 AM
CVE-2024-55591 - It's that day of the week again! Good job Fortinet 👏
January 15, 2025 at 10:24 AM
At this point, if I just blindly post this meme on any given day it's got a very high chance of being relevant 🤣
January 9, 2025 at 12:19 PM
An unknown service has somehow identified the domain of my Chrome exploitation framework and periodically scans it with an old version of Chrome... 🤦‍♂️
January 6, 2025 at 6:06 PM
Post a game you got for Christmas

The first PC game I ever played came with the brand new 66 MHz Intel pentium PC my brother and I got for Christmas when I was 10.
December 25, 2024 at 3:28 PM
CVE-2023-34990 🤦‍♂️🤦‍♂️
December 18, 2024 at 2:26 PM
These two sentences are so totally contradictory 😆 Never change LinkedIn grifters, never change.
December 16, 2024 at 2:38 PM
November 22, 2024 at 5:00 PM
Is this the best 40th birthday cake a chap could wish for?? Well I for one can't think of a better one! Made by my fantastically talented wife and daughter ❤️
November 22, 2024 at 3:46 PM
Post a pic YOU took (no description) to bring some zen to the timeline
November 16, 2024 at 9:21 PM
I've been working on some fun shellcode 😈
October 11, 2023 at 1:49 PM