the researcher used the Linux client to do the RE work... so I guess it's not just for 'bug' but also for free security audit! (2 CVE were reported)