4573 | Bypassing Firebase authorization to create custom goo.gl subdomains |
Logic flaw
IDOR |
Google |
Thomas Orlita (@ThomasOrlita) |
Bug Bounty | 2018-09-21 | 2023-06-13 |
3689 | Exploiting Insecure Firebase Database! |
Insecure Firebase database
Android |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2020-02-04 | 2023-06-13 |
3208 | Firebase Cloud Messaging Service Takeover: A small research that led to 30k$+ in bounties |
Hardcoded API keys
Information disclosure |
Google |
Abss (@absshax) |
Bug Bounty | 2020-08-17 | 2023-06-13 |
2636 | Lets Learn English - Hacking 10M+ Users |
AWS misconfiguration
Insecure Firebase database
OTP bypass
Account takeover
Logic flaw |
NA |
Aseem Shrey (@AseemShrey) |
Bug Bounty | 2021-04-17 | 2023-06-13 |
1912 | Write Up – Private Bug Bounty: Firebase Database Exposed By Misconfiguration – $2,000 USD |
Android
Insecure Firebase database |
NA |
Omar Espino (@omespino) |
Bug Bounty | 2022-01-17 | 2023-06-13 |
1401 | Penetration Testing Firebase Web Applications |
Firebase
Information disclosure |
NA |
Bhashit Pandya (@x30r_) |
Bug Bounty | 2022-07-03 | 2023-06-13 |
830 | Firebase: Insecure by Default (feat. that one time our classmates tried to sue us) |
Hardcoded API keys |
Fizz |
Aditya Saligrama (@saligrama_a) |
Bug Bounty | 2022-11-14 | 2023-06-13 |
785 | Dodging OAuth origin restrictions for Firebase spelunking |
OAuth
Security misconfiguration
Authentication flaw |
NA |
Aditya Saligrama (@saligrama_a) |
Bug Bounty | 2022-11-23 | 2023-06-13 |
767 | Firebase Exploit bug bounty |
Security misconfiguration
Firebase |
NA |
Damaidec |
Bug Bounty | 2022-11-27 | 2023-06-13 |
107 | Testing a new encrypted messaging app%27s extraordinary claims |
Android
Firebase
Cryptographic issues
Privacy issue
Information disclosure |
Converso |
Crnković |
Bug Bounty | 2023-05-10 | 2023-06-13 |