Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3621The unexpected Google wide domain check bypass Logic flaw Google David Schütz (@xdavidhu) Bug Bounty2020-03-082023-06-13
2907Stealing Your Private YouTube Videos, One Frame at a Time IDOR Google David Schütz (@xdavidhu) Bug Bounty2021-01-112023-06-13
2884The Embedded YouTube Player Told Me What You Were Watching (and more) Information disclosure Google David Schütz (@xdavidhu) Bug Bounty2021-01-182023-06-13
2662CSRF in YouTube Leanback API CSRF Google David Schütz (@xdavidhu) Bug Bounty2021-04-052023-06-13
2657I Built a TV That Plays All of Your Private YouTube Videos CSRF Google David Schütz (@xdavidhu) Bug Bounty2021-04-052023-06-13
2624Auth Bypass in Google Workspace Real Time Collaboration Authentication bypass Information disclosure Google David Schütz (@xdavidhu) Bug Bounty2021-04-202023-06-13
2598De-anonymising Anonymous Animals in Google Workspace Privacy issue Information disclosure Google David Schütz (@xdavidhu) Bug Bounty2021-04-292023-06-13
2552Auth Bypass in https://nearbydevices-pa.googleapis.com Broken Access Control Google David Schütz (@xdavidhu) Bug Bounty2021-05-162023-06-13
2549Clickjacking in Nearby Devices Dashboard Clickjacking Google David Schütz (@xdavidhu) Bug Bounty2021-05-172023-06-13
2546Path Traversal in MobileSafari Path traversal Apple David Schütz (@xdavidhu) Bug Bounty2021-05-182023-06-13
2524Bypassing restricted port protection in WebKit Browser hacking Apple David Schütz (@xdavidhu) Bug Bounty2021-05-262023-06-13
2426IDOR on clientauthconfig.googleapis.com IDOR Google David Schütz (@xdavidhu) Bug Bounty2021-07-082023-06-13
2414Unencrypted HTTP Links to Google Scholar in Search MiTM Google David Schütz (@xdavidhu) Bug Bounty2021-07-132023-06-13
2161Auth Bypass in Google Assistant Insecure deeplink Google David Schütz (@xdavidhu) Bug Bounty2021-10-102023-06-13
2067URL whitelist bypass in https://cxl-services.appspot.com Privilege escalation URL validation bypass SSRF Google David Schütz (@xdavidhu) Bug Bounty2021-11-172023-06-13
1954Fixing the Unfixable: Story of a Google Cloud SSRF SSRF Google David Schütz (@xdavidhu) Bug Bounty2021-12-312023-06-13
1847Auth Bypass in com.google.android.googlequicksearchbox Authentication bypass Google David Schütz (@xdavidhu) Bug Bounty2022-02-062023-06-13
1846Auth Bypass in Google Assistant Information disclosure Authentication bypass Google David Schütz (@xdavidhu) Bug Bounty2022-02-062023-06-13
1660CloudKit Share Records leak the title of private iCloud files IDOR Broken Access Control Apple David Schütz (@xdavidhu) Bug Bounty2022-04-052023-06-13
1138Viewing Instagram live streams anonymously without notifying the host IDOR Logic flaw Privacy issue Meta / Facebook David Schütz (@xdavidhu) Bug Bounty2022-09-022023-06-13
846Accidental $70k Google Pixel Lock Screen Bypass Lock screen bypass Authentication bypass Android Google David Schütz (@xdavidhu) Bug Bounty2022-11-102023-06-13
798Header spoofing via a hidden parameter in Facebook Batch GraphQL APIs GraphQL Security misconfiguration Meta / Facebook David Schütz (@xdavidhu) Bug Bounty2022-11-212023-06-13