Web + Mobile Security Researcher

Security begins where the intended model breaks.

I’m Woonghee Lee (이웅희), a Ph.D. candidate at Korea University’s Information System Security Lab. I measure how real-world web and mobile systems diverge from their security assumptions.

Focus
Web & Mobile
Security impact
2 CVEs
Based in
Seoul, Korea
ISSLAB / KOREA UNIVERSITY
Portrait of Woonghee Lee

01 / Publications

Selected work

Peer-reviewed research in leading web and security venues. My name is highlighted.

TheWebConf 2026

SPCA: Stream Parser Confusion Attack for Web Application Firewall Evasion in HTTP/2

Kyungrok Choi*, Woonghee Lee*, Junbeom Hur

* Equal contribution
Paper
ACM CCS 2025

Deep Dive into In-app Browsers: Uncovering Hidden Pitfalls in Certificate Validation

Woonghee Lee, Junbeom Hur, Hyunsoo Kwon

Paper
ASIACCS 2024

Beneath the Phishing Scripts: A Script-Level Analysis of Phishing Kits and Their Impact on Real-World Phishing Websites

Woonghee Lee, Junbeom Hur, Doowon Kim

Paper
TheWebConf 2024

PhishinWebView: Analysis of Anti-Phishing Entities in Mobile Apps with WebView Targeted Phishing

Yoonjung Choi*, Woonghee Lee*, Junbeom Hur

* Equal contribution
Paper

02 / Experience & academic life

Beyond the paper

Research experience, talks, awards, and service beyond peer-reviewed publications.

2022.07—08

Research experience

Visiting Researcher

University of Tennessee · Hosted by Prof. Doowon Kim

Talks

  1. Deep Dive into In-app Browsers

    ACM CCS · Taipei, Taiwan

  2. Security Threats in Mobile In-app Browsers

    Ph.D. Job Talk · SWCS · Seoul

  3. Beneath the Phishing Scripts

    ACM ASIACCS · Singapore

  4. PhishinWebView

    The ACM Web Conference · Singapore

Awards & service

2025

KISA Director’s Award

Outstanding Award, National Cryptographic Competition

2024

Excellence Awards for Research Papers

Korea University College of Informatics · Spring & Fall

2024—26

Conference reviewer

The Web Conference (WWW)

2022

Teaching assistant

Discrete Mathematics · Information Security

03 / Responsible disclosure

Two CVEs from SPCA.

Coordinated disclosure of our HTTP/2 request-body inspection findings led to two CVE assignments for AWS WAF deployments.

AWS acknowledged Kyungrok Choi, Woonghee Lee, and Junbeom Hur for the coordinated vulnerability disclosure.

AWS security bulletin

04 / Research focus

Research focus

I study the gap between systems as designed and systems in the wild—measuring security failures across browsers, mobile ecosystems, phishing, and web infrastructure.

01

Certificate validation in mobile & in-app browsers

Testing whether embedded browsing surfaces preserve the trust guarantees users expect from the open web.

02

Measurement of the phishing ecosystem

Studying phishing kits, shared scripts, infrastructure, and evasion techniques through large-scale measurements.

03

Privacy leakage in the Android ecosystem

Following sensitive data across apps, in-app browsers, WebViews, and the third-party SDKs connecting them.

04

Security of web infrastructure

Analyzing security boundaries and unexpected interactions among CAPTCHAs, WAFs, CDNs, and modern protocols.

05 / Contact

Let’s examine the edge cases.

Interested in collaboration around web security, mobile ecosystems, or large-scale security measurement? I’d be glad to hear from you.