5148 | Samsung Galaxy Apps MiTM vulnerabilities |
MiTM
Android |
Samsung |
Simone Margaritelli (@evilsocket) |
Bug Bounty | 2016-08-17 | 2023-06-13 |
5071 | Android Browser All Versions - Address Bar Spoofing Vulnerability - CVE-2015-3830 |
Address Bar Spoofing |
Google |
Rafay Baloch (@rafaybaloch) |
Bug Bounty | 2017-06-01 | 2023-06-13 |
5067 | Android Browser Same Origin Policy Bypass < 4.4 - CVE-2014-6041 |
SOP bypass |
Google |
Rafay Baloch (@rafaybaloch) |
Bug Bounty | 2017-06-01 | 2023-06-13 |
5066 | A Tale Of Another SOP Bypass In Android Browser < 4.4 |
SOP bypass |
Google |
Rafay Baloch (@rafaybaloch) |
Bug Bounty | 2017-06-01 | 2023-06-13 |
5061 | WhatsApp — Dos Vulnerability In iOS & Android |
DoS |
Meta / Facebook |
Vishnu Prasad P G (@vishnuprasadnta) |
Bug Bounty | 2017-06-07 | 2023-06-13 |
5043 | WhatsApp — DoS Vulnerability In iOS & Android |
DoS |
Meta / Facebook |
Vishnuraj |
Bug Bounty | 2017-07-07 | 2023-06-13 |
4902 | Content Injection in DuoLingo’s TinyCards App for Android [CVE-2017-16905] |
Content injection |
DuoLingo |
Nightwatch Cybersecurity (@nightwatchcyber) |
Bug Bounty | 2018-01-04 | 2023-06-13 |
4858 | How I was able to remotely crash any android user’s instagram app and was paid a mere 500$ for it. |
Android
DoS |
Meta / Facebook |
Waleed Ahmed |
Bug Bounty | 2018-02-15 | 2023-06-13 |
4833 | CVE-2017-13253: Buffer overflow in multiple Android DRM services |
Memory corruption
Local Privilege Escalation |
Google |
Tamir Zahavi-Brunner (@tamir_zb) |
Bug Bounty | 2018-03-15 | 2023-06-13 |
4767 | Whatsapp- DOS vulnerability on Android/iOS/Web |
DoS |
Meta / Facebook |
Pratheesh P Narayanan (@PRATHEESH_PPN) |
Bug Bounty | 2018-05-15 | 2023-06-13 |
4663 | Discovering and Exploiting a Vulnerability in Android’s Personal Dictionary (CVE-2018-9375) |
Privilege escalation
Android |
Google |
Daniel Kachakil (@Kachakil) |
Bug Bounty | 2018-08-01 | 2023-06-13 |
4560 | Hacking the Subway Android app |
Logic flaw
Authorization flaw |
Subway |
Wesley Gahr (@wesley_gahr) |
Bug Bounty | 2018-09-28 | 2023-06-13 |
4515 | DoS on Facebook Android app using 65530 characters of ZERO WIDTH NO-BREAK SPACE. |
DoS |
Meta / Facebook |
Rahul Kankrale (@RahulKankrale) |
Bug Bounty | 2018-10-25 | 2023-06-13 |
4506 | CVE-2018-9411: New critical vulnerability in multiple high-privileged Android services |
Memory corruption |
Google |
Tamir Zahavi-Brunner (@tamir_zb) |
Bug Bounty | 2018-10-30 | 2023-06-13 |
4485 | CVE-2018-9539: Use-after-free vulnerability in privileged Android service |
Memory corruption
Use-After-Free |
Google |
Tamir Zahavi-Brunner (@tamir_zb) |
Bug Bounty | 2018-11-09 | 2023-06-13 |
4376 | Facebook Android Application |
Authorization flaw |
Meta / Facebook |
Ashley King (@AshleyKingUK) |
Bug Bounty | 2019-01-05 | 2023-06-13 |
4305 | Third Party Android App Storing Facebook Data Insecurely (Facebook Data Abuse Program) |
Information disclosure
Missing authentication |
Meta / Facebook |
Nightwatch Cybersecurity (@nightwatchcyber) |
Bug Bounty | 2019-02-14 | 2023-06-13 |
4279 | SHAREit Multiple Vulnerabilities Enable Unrestricted Access to Adjacent Devices’ Files |
Android
Arbitrary file download
Authentication bypass |
SHAREit |
Abdulrahman Nour (@aboodnour) |
Bug Bounty | 2019-02-25 | 2023-06-13 |
4238 | How to hunt for Malvertising ads on Android |
Android |
NA |
Kyle (@B3nac) |
Bug Bounty | 2019-03-21 | 2023-06-13 |
4082 | How I Hacked the Microsoft Outlook Android App and Found CVE-2019-1105 |
XSS |
Microsoft |
Bryan Appleby (@bryapp)< |
Bug Bounty | 2019-06-21 | 2023-06-13 |
4047 | Facebook Bug bounty page admin disclose bug {Facebook Android app} |
Information disclosure |
Meta / Facebook |
Yusuf Furkan (@h1_yusuf) |
Bug Bounty | 2019-07-12 | 2023-06-13 |
3959 | One Bug To Rule Them All: Modern Android Password Managers and FLAG_SECURE Misuse |
Information disclosure
Content leak |
1Password
Keeper
Dashlane |
Lorenzo Stella (@lorenzostella) |
Bug Bounty | 2019-08-22 | 2023-06-13 |
3950 | Address bar spoofing in Firefox Lite for Android ...and the idiocy that followed |
Address Bar Spoofing
URL spoofing |
Mozilla |
Piyush Raj (@0x48piraj) |
Bug Bounty | 2019-08-01 | 2023-06-13 |
3922 | How two dead accounts allowed remote crash of any instagram android user |
DoS |
Meta / Facebook |
Valerio brussani (@val_brux) |
Bug Bounty | 2019-09-13 | 2023-06-13 |
3892 | How a double-free bug in WhatsApp turns to RCE |
Memory corruption
RCE
Android |
Meta / Facebook |
Awakened |
Bug Bounty | 2019-10-02 | 2023-06-13 |