A research team from the Ulsan National Institute of Science and Technology (UNIST) has become the first Korean group to win the Internet Defense Prize at the 35th Usenix Security Symposium. This recognition highlights their work in identifying how common browser interactions create significant security vulnerabilities.
The team presented a paper titled BUIzz: Finding Policy Enforcement Bugs via Interaction Simulation on the Browser User Interface. Their research proves that routine actions such as right-clicking a link, duplicating tabs, or using split-screen views can trigger unexpected bugs within popular browsers like Chrome and Firefox.
Over the course of their project, the researchers identified 35 security bugs and three functional bugs. These findings led to 14 confirmed fixes and seven Common Vulnerabilities and Exposures (CVE) designations. The group received $14,700 in bug bounties for their contributions to browser security.
The Internet Defense Prize is funded by Meta and honors research that improves the security of global internet systems. Since its inception in 2014, the UNIST team is the first from Korea to receive this honor. The symposium featured over 3,000 paper submissions, with only 362 accepted for presentation. The UNIST team will receive $25,000 in additional research funding as part of their win.

