5286 | Google.com cross site scripting and privilege escalation in Consumer Surveys |
Stored XSS
Authorization flaw |
Google |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2013-01-03 | 2023-06-13 |
5275 | How I found my way into Instagram%27s Ganglia, and a bug with Facebook likes. |
Reflected XSS
IDOR |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2013-07-23 | 2023-06-13 |
5274 | SQL injections in Nokia sites. |
SQL injection |
Nokia |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2013-07-30 | 2023-06-13 |
5269 | Facebook CSRF leading to full account takeover (fixed) |
CSRF
Account takeover |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2013-10-18 | 2023-06-13 |
5267 | Facebook bug bounty: secondary damage (one report that leads to more bugs), fairness, and why I really like reporting to Facebook |
CSRF |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2013-10-21 | 2023-06-13 |
5241 | Step-by-step: exploiting SQL injection(s) in Oculus%27 website. |
SQL injection |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2014-09-05 | 2023-06-13 |
5233 | Reading local files from Facebook%27s server (fixed) |
LFI
Unrestricted file upload |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2014-12-06 | 2023-06-13 |
5219 | Race conditions on Facebook, DigitalOcean and others (fixed) |
Race condition |
Meta / Facebook
DigitalOcean
LastPass |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2015-04-27 | 2023-06-13 |
5216 | The easiest bug bounties I have ever won |
IDOR |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2015-07-13 | 2023-06-13 |
5161 | Race conditions on the web |
Race condition |
Cobalt.io
Meta / Facebook
MEGA
Keybase |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2016-07-12 | 2023-06-13 |
5159 | Stealing Facebook access_tokens using CSRF in device login flow |
CSRF
OAuth
Information disclosure |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2016-07-19 | 2023-06-13 |
4895 | Hacking Facebook accounts using CSRF in Oculus-Facebook integration |
CSRF |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2018-01-15 | 2023-06-13 |
4865 | Taking over Facebook accounts using Free Basics partner portal |
Information disclosure
IDOR |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2018-02-07 | 2023-06-13 |
4838 | Getting any Facebook user%27s friend list and partial payment card details |
Information disclosure
IDOR |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2018-03-09 | 2023-06-13 |
3256 | CVE-2020–9854: "Unauthd" |
MacOS
Local Privilege Escalation
SIP bypass |
Apple (macOS) |
Ilias Morad (@A2nkF_) |
Bug Bounty | 2020-08-01 | 2023-06-13 |
2113 | Microsoft finds new macOS vulnerability, Shrootless, that could bypass System Integrity Protection |
SIP bypass
Local Privilege Escalation |
Apple |
Microsoft Security Vulnerability Research (MSVR) |
Bug Bounty | 2021-10-28 | 2023-06-13 |
1887 | Technical Analysis of CVE-2022-22583: Bypassing macOS System Integrity Protection (SIP) |
MacOS
SIP bypass |
Apple |
Perception Point |
Bug Bounty | 2022-01-27 | 2023-06-13 |
1313 | CVE-2022-26712: The POC for SIP-Bypass Is Even Tweetable |
MacOS
SIP bypass |
Apple |
Mickey Jin (@patch1t) |
Bug Bounty | 2022-07-26 | 2023-06-13 |
837 | CVE-2019-8561: A Hard-to-Banish PackageKit Framework Vulnerability in macOS |
MacOS
Local Privilege Escalation
SIP bypass |
Apple |
Mickey Jin (@patch1t) |
Bug Bounty | 2022-11-11 | 2023-06-13 |
672 | Diving into an Old Exploit Chain and Discovering 3 new SIP-Bypass Vulnerabilities |
MacOS
Local Privilege Escalation
SIP bypass |
Apple (macOS) |
Mickey Jin (@patch1t) |
Bug Bounty | 2022-12-20 | 2023-06-13 |
670 | A Technical Analysis of CVE-2022-22583 and CVE-2022-32800 |
MacOS
Local Privilege Escalation
SIP bypass |
Apple (macOS) |
Mickey Jin (@patch1t) |
Bug Bounty | 2022-12-21 | 2023-06-13 |
595 | Bad things come in large packages: .pkg signature verification bypass on macOS |
Local Privilege Escalation
GateKeeper bypass
SIP bypass
MacOS |
Apple |
Sector 7 (@sector7_nl) |
Bug Bounty | 2023-01-13 | 2023-06-13 |
542 | Kamailio’s exec module considered harmful |
OS command injection
SIP |
Kamailio |
Ali Norouzi |
Bug Bounty | 2023-01-26 | 2023-06-13 |
328 | The Silent Spy Among Us: Modern Attacks Against Smart Intercoms |
IoT
OS command injection
Missing authentication
MiTM
SIP |
Akuvox |
Claroty%27s Team82 (@Claroty) |
Bug Bounty | 2023-03-09 | 2023-06-13 |
43 | New macOS vulnerability, Migraine, could bypass System Integrity Protection |
SIP bypass |
Apple (macOS) |
Jonathan Bar Or (@yo_yo_yo_jbo) |
Bug Bounty | 2023-05-30 | 2023-06-13 |