Early access — the directory is still filling out, and every rating here is a reported experience.

Researcher profile

Maliq Barnard
Maliq Barnard ✓ verified
@sahwe · member since August 2026
Verified researcher Multi-platform Contributor Early member
53/100
Contributing
Reputation
Verified platform accounts · portable reputation
HackerOne · sahwe
138Reputation
#13,731Rank
0.17Signal
18.3Impact
4Badges
0Disclosed
GitHub · smoke-wolf
Security-release credits
Credited by Apple ×1
Additional recognition macOS Tahoe 26.6 RemoteServiceDiscovery BR2026-0000-001186 ✓ claimed vendor credited Maliq Barnard
BugBadge · portable credential
BR-RSNN-9W25

Maliq Barnard can attach a fresh, time-limited attestation of this badge to a report on any platform. It attests track record — never a legal identity, and never a guarantee.

View badge
2
Reviews written
2
Programs reviewed
12
Reports represented
1
Helpful votes
How they review
3.5 avg rating given
1 positive 1 mixed 0 negative
Where they hunt
Direct / email 1
Bugcrowd 1

Programs reviewed

2

Reviews

National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
I submitted 3 SSRF findings across the NASA VRP scope - they all went informative
neutral

As the tittle says, I had three. SSRF reports go to NASA's VPR before they were all closed as informative under P5. Which, while unfortunate, had the reports triaged in under 2 days. Which is always a quality I as a research greatly appreciate from programs and vendors.

via Bugcrowd reports 3 1st reply Within 3 days resubmit yes
Maliq Barnard ✓ verified · Aug 3, 2026 · Share ↗ 0 helpful
Apple Security Bounty
Responsive, fair, and quick.
positive

I have spent the last 4 months interacting with the Apple security response team (SRT). They have been incredibly thorough with their evaluations, informative closes are almost always accompanied by a detailed explanation as to why it is not applicable. They are fast with triage and will usually move on your report within 48 hours. The surface however, is increasingly hardened as automated security research has massively accelerated the speed at which it used to take. As such, the most critical note when submitting to Apple, always, and I mean always, prove the impact, weaponize the exploit, demonstrate the chain. If any part reads as theoretical, it will not strengthen the case for the report.

via Direct / email reports 9 paid $500 – $2k 1st reply Within 3 days resubmit yes
Maliq Barnard ✓ verified · Aug 3, 2026 · Share ↗ 1 helpful