Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5221Telegram App Store Secret-Chat Messages in Plain-Text Database Privacy issue Information disclosure Telegram Jon Paterson (@shellprompt) Bug Bounty2015-02-232023-06-13
4654FakesApp: A Vulnerability in WhatsApp Content spoofing Authorization flaw Privacy issue Meta / Facebook Dikla Barda Bug Bounty2018-08-072023-06-13
3932Telegram addresses another privacy issue Logic flaw Privacy issue Telegram Dhiraj (@RandomDhiraj) Bug Bounty2019-09-092023-06-13
3588VPN bypass vulnerability in Apple iOS Privacy issue Apple Proton Team Bug Bounty2020-03-252023-06-13
3542Here is the Non Technical write-up on Technical Bug for My Second Bounty of $xxxx From Facebook Logic flaw Privacy issue Meta / Facebook Ashok Chapagai (@ashokcpg) Bug Bounty2020-04-172023-06-13
3220Improper Implementation of My Status video time limit in WhatsApp Logic flaw Privacy issue Android Meta / Facebook Vishal Ranjan Bug Bounty2020-08-142023-06-13
3219Deleted data stored permanently on Instagram? Facebook Bug Bounty 2020 Logic flaw Privacy issue Meta / Facebook Saugat Pokharel (@saugatpk5) Bug Bounty2020-08-142023-06-13
3077TikTok fixes privacy issue discovered by Check Point Research Information disclosure TikTok Eran Vaknin Bug Bounty2020-10-262023-06-13
2819The "P" in Telegram stands for Privacy Privacy issue Telegram Dhiraj (@RandomDhiraj) Bug Bounty2021-02-112023-06-13
2617PrivateDrop: Breaking and Fixing Apple AirDrop Privacy issue Information disclosure Apple Alexander Heinrich Bug Bounty2021-04-212023-06-13
2615Telegram bug bounties: XSS, privacy issues, official bot exploitation and more… XSS Authorization flaw DoS NA Davide Bug Bounty2021-04-222023-06-13
2598De-anonymising Anonymous Animals in Google Workspace Privacy issue Information disclosure Google David Schütz (@xdavidhu) Bug Bounty2021-04-292023-06-13
2594How I was able to Retrieve your Personal Documents using the Wayback Machine! Privacy issue Information disclosure NA Savir Suda (@savxiety) Bug Bounty2021-04-302023-06-13
2399Hacking Xiaomi%27S Android Apps - Part 1 Android Information disclosure Open redirect Privacy issue Xiaomi Ameya (@iamTakeMyHand) Bug Bounty2021-07-192023-06-13
2319CVE-2021-22929 – Brave Browser 1.27 and below permanently logs the server connection time for all v2 tor domains to ~/.config/BraveSoftware /Brave-Browser/tor/data/tor.log Privacy issue Information disclosure Brave Software sickcodes (@sickcodes) Bug Bounty2021-08-162023-06-13
2258Play the music and bypass TCC aka CVE-2020-29621 Privacy issue MacOS Apple Wojciech Reguła (@_r3ggi) Bug Bounty2021-09-022023-06-13
2236Change home directory and bypass TCC aka CVE-2020-27937 Privacy issue MacOS Apple Wojciech Reguła (@_r3ggi) Bug Bounty2021-09-092023-06-13
2194Disclosure of three 0-day iOS vulnerabilities and critique of Apple Security Bounty program Information disclosure Local Privilege Escalation Privacy issue Apple Denis Tokarev / illusionofchaos Bug Bounty2021-09-242023-06-13
2184Telegram users%27 privacy has been violated again. Messenger representatives demand not to disclose details Privacy issue Telegram ne555 Bug Bounty2021-09-292023-06-13
2026How I accessed the Sensitive document which I had already deleted Privacy issue NA Pawan Chhabria (@heybenchmarkkk) Bug Bounty2021-12-042023-06-13
1959WhatsApp for Android Retains Deleted Contacts Locally Privacy issue Meta / Facebook Nightwatch Cybersecurity (@nightwatchcyber) Bug Bounty2021-12-302023-06-13
1930New macOS vulnerability, “powerdir,” could lead to unauthorized user data access Privacy issue MacOS Apple Microsoft 365 Defender Research Team Bug Bounty2022-01-102023-06-13
1858How I Tracked You Around The Globe 🌎 Information disclosure Privacy issue Google (Waze) 0xdroopy (@NikhilK50866227) Bug Bounty2022-02-022023-06-13
1773Skype extension: All functionality broken? Still exploitable! Information disclosure Privacy issue Microsoft Wladimir Palant (@WPalant) Bug Bounty2022-03-012023-06-13
1489De-Anonymization attacks against Proton services Privacy issue Information disclosure HTML injection Local Privilege Escalation Proton AG Ruben Santamarta (@reversemode) Bug Bounty2022-06-082023-06-13