This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.
| Michel Zalewski | |
|---|---|
| Name | Michel Zalewski |
| Occupation | Security researcher, software engineer, author |
| Known for | Browser security, web application vulnerabilities, fuzzing, secure coding |
| Notable works | "The Tangled Web" |
Michel Zalewski is a computer security researcher and software engineer noted for contributions to web browser security, exploit mitigation analysis, and secure coding practices. He has influenced Mozilla Corporation, Google, Microsoft Corporation, Apple Inc., Facebook, and academic groups through vulnerability research, tooling, and public writing. His work spans vulnerability discovery, exploit technique analysis, fuzzing methodologies, and outreach to developer communities and standards organizations.
Born and raised in Europe, Zalewski pursued studies in computer science and software engineering, engaging with technical communities in Warsaw and Paris before relocating professionally to Western technology centers. He developed an early interest in systems programming, contributing to projects that intersected with researchers at University of Warsaw, École Polytechnique, and later collaborating informally with engineers from Carnegie Mellon University and Massachusetts Institute of Technology. His formative interactions included attendance at conferences such as Black Hat Briefings, DEF CON, and Usenix events, where he exchanged research with contemporaries from Sun Microsystems, Intel Corporation, and Red Hat.
Zalewski has worked as an independent security consultant and researcher, providing analysis and tools adopted by engineers at Google Chrome, Mozilla Firefox, Microsoft Edge, and other browser teams. His consulting engagements and public analyses reached audiences at OWASP, IETF, and major vendor security groups including Cisco Systems and Oracle Corporation. He has collaborated with vulnerability disclosure programs run by HackerOne and Bugcrowd, and his findings influenced mitigations discussed at RSA Conference, Black Hat USA, and CanSecWest.
Throughout his career he has contributed to open source projects and mailing lists used by developers at GitHub, Kernel.org, and contributors to Chromium. His technical correspondence and advisories were read by security teams at Amazon Web Services, Cloudflare, and Yandex. He engaged with standards bodies and working groups related to web technologies at World Wide Web Consortium and Internet Engineering Task Force.
Zalewski produced influential analyses of browser internals, sandboxing, memory corruption, and exploitation techniques that informed hardened implementations at Google, Mozilla Corporation, Microsoft Corporation, and Apple Inc.. He developed fuzzing approaches and tooling that were referenced by researchers at University of California, Berkeley, ETH Zurich, and Technische Universität München, and adopted in corporate fuzzing pipelines at Facebook and Amazon. His work examined interaction between just-in-time compilation engines such as those in V8 JavaScript Engine and SpiderMonkey, and edge-case behaviors in document rendering engines like WebKit and Blink.
Zalewski's analyses touched on attack surfaces involving media libraries used by Adobe Systems products and codecs leveraged by VLC media player contributors, and informed mitigations applied by teams at Apple Inc. and Microsoft Corporation. He documented subtle parsing errors and race conditions that intersected with libraries maintained by organizations such as OpenSSL, LibreSSL, and BoringSSL, contributing to community knowledge on hardening cryptographic stacks. His proposals for safer APIs and sanitizer integration were considered by implementers at LLVM and GCC projects, and referenced in discussions with maintainers of glibc and musl.
Zalewski authored technical essays and a widely cited book that analyzed the complexities of browser security and secure software design, which influenced engineers at Google Chrome, Mozilla Firefox, Microsoft Edge, and researchers at SRI International and RAND Corporation. He presented findings at major security conferences including Black Hat USA, DEF CON, RSA Conference, and CanSecWest, engaging audiences from NSA-affiliated research groups, corporate security teams from Intel Corporation and AMD, and academic attendees from Stanford University and University of Cambridge. His blog posts and whitepapers were discussed on community platforms alongside posts by security researchers at Tavis Ormandy, Charlie Miller, and groups such as Project Zero.
He contributed chapters and essays to collected works alongside authors from O'Reilly Media and appeared on panels with representatives from OWASP and IETF to debate secure defaults, sandbox boundaries, and responsible vulnerability disclosure practices.
Throughout his public career, some of Zalewski's disclosures and critique of vendor practices generated controversy and debate among engineers at Google, Mozilla, and Microsoft Corporation, as well as legal and policy teams at affected companies such as Adobe Systems and Oracle Corporation. Debates centered on coordinated disclosure timelines, exploit proof-of-concept publication, and balancing research transparency with operational risk—issues also discussed in forums involving EFF and ACLU technology policy groups. At times his critiques prompted responses from corporate security teams and led to follow-up patches and public advisories from vendors including Apple Inc. and Facebook.
Legal scrutiny in the field has often involved liaison with disclosure programs operated by HackerOne and coordination with national CERT organizations such as CERT Coordination Center. Discussions arising from his work contributed to evolving norms and best practices for vulnerability reporting and vendor engagement adopted across the broader security community.
Category:Computer security researchers Category:Authors on computer security