Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3165Universal XSS in Android WebView (CVE-2020-6506) Universal XSS Google Microsoft Twitter Alesandro Ortiz (@AlesandroOrtizR) Bug Bounty2020-09-102023-06-13
1703When Equal is Not, Another WebView Takeover Story Android NA Dimitrios Valsamaras (@Ch0pin) Bug Bounty2022-03-222023-06-13
1250Identity Confusion in WebView-based Mobile App-in-app Ecosystems Android iOS Alipay Lei Zhang, Zhibo Zhang, Ancong Liu, Yinzhi Cao, Xiaohan Zhang, Yanjun Chen, Yuan Zhang, Guangliang Yang & Min Yang Bug Bounty2022-08-112023-06-13
773WebView XSS, account takeover Webview XSS Android Account takeover Improper Export of Android Application Components NA shafou Bug Bounty2022-11-262023-06-13
764Multiple Vulnerabilities found in Airtel Android Application Arbitrary Code Execution URL validation bypass Symlink attack XSS Android Webview Airtel Google Gaurang Bhatnagar (@hax0rgb) Bug Bounty2022-11-272023-06-13
5842022 Microsoft Teams RCE RCE Insecure deeplink Webview Microsoft @adm1nkyj1 Bug Bounty2023-01-162023-06-13
427Escaping misconfigured VSCode extensions Path traversal DNS rebinding XSS HTML injection Webview CSP bypass Microsoft (SARIF viewer & Live Preview) Vasco Franco Bug Bounty2023-02-212023-06-13
403Escaping well-configured VSCode extensions (for profit) Electron Webview Path traversal Microsoft Vasco Franco Bug Bounty2023-02-232023-06-13
216Steal authentication token with one-click on misconfigured WebView. Android Webview Account takeover NA Kerolos A. Saber (@0xWise) Bug Bounty2023-04-082023-06-13