3868 | NFC Beaming Bypasses Security Controls in Android [CVE-2019-2114] |
NFC
Android |
Google |
Nightwatch Cybersecurity (@nightwatchcyber) |
Bug Bounty | 2019-10-24 | 2023-06-13 |
3862 | Android Reddit App leaks images |
Information disclosure |
Reddit |
Eric Urban |
Bug Bounty | 2019-10-29 | 2023-06-13 |
3855 | Live Video facebook application (Android) its not expired when log out the device on https://www.facebook.com/settings?tab=security§ion=sessions&view |
Logic flaw |
Meta / Facebook |
Naufal Septiadi |
Bug Bounty | 2019-10-30 | 2023-06-13 |
3805 | XSS Stored On [ Outlook Web — Outlook Android App ] |
Stored XSS |
Microsoft |
ElMahdi Mrhassel (@ElMrhassel) |
Bug Bounty | 2019-11-28 | 2023-06-13 |
3768 | Full Account Takeover (Android Application) |
Information disclosure
Account takeover |
NA |
Vishal Bharad |
Bug Bounty | 2019-12-21 | 2023-06-13 |
3689 | Exploiting Insecure Firebase Database! |
Insecure Firebase database
Android |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2020-02-04 | 2023-06-13 |
3656 | Hacking SMS API Service Provider of a Company |Android App Static Security Analysis | Bug Bounty POC |
Information disclosure
Hardcoded credentials |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2020-02-19 | 2023-06-13 |
3518 | Indirect UXSS issue on a private Android target app |
Universal XSS |
NA |
Kunal pandey (@kunalp94) |
Bug Bounty | 2020-04-29 | 2023-06-13 |
3446 | XSS Stored On Messages In [ Outlook Web — Outlook Android App ] |
Stored XSS |
Microsoft |
ElMahdi Mrhassel (@ElMrhassel) |
Bug Bounty | 2020-05-28 | 2023-06-13 |
3357 | API Endpoint leads to Account Takeover In Android Application |
Exposed token generation endpoint
Information disclosure |
NA |
Adesh Nandkishor kolte (@AdeshKolte) |
Bug Bounty | 2020-06-28 | 2023-06-13 |
3321 | From N/A to Resolved For BackBlaze Android App[Hackerone Platform] Bucket Takeover |
Hardcoded credentials
Information disclosure |
BackBlaze |
Sahil Tikoo (@viperbluff) |
Bug Bounty | 2020-07-09 | 2023-06-13 |
3320 | Global grant uri in Android 8.0-9.0 (2018 year) |
Authorization flaw |
Google |
Dzmitry Lukyanenka (@vulnano) |
Bug Bounty | 2020-07-09 | 2023-06-13 |
3298 | Android pin bypass with rate limiting |
Lack of rate limiting
Authentication bypass |
NA |
Baluz (@t3chman) |
Bug Bounty | 2020-07-18 | 2023-06-13 |
3297 | Creative Android pin bypass with Race conditon |
Race condition
Authentication bypass |
NA |
Baluz (@t3chman) |
Bug Bounty | 2020-07-18 | 2023-06-13 |
3285 | Hunting Android Application Bugs Using Android Studio. |
Authorization flaw
Client-side enforcement of server-side security
Information disclosure |
NA |
Tarek Mohammed (@Conan0x3) |
Bug Bounty | 2020-07-24 | 2023-06-13 |
3241 | Smear phishing: a new Android vulnerability |
Phishing
Android |
Google |
Jim Fisher (@MrJamesFisher) |
Bug Bounty | 2020-08-06 | 2023-06-13 |
3220 | Improper Implementation of My Status video time limit in WhatsApp |
Logic flaw
Privacy issue
Android |
Meta / Facebook |
Vishal Ranjan |
Bug Bounty | 2020-08-14 | 2023-06-13 |
3214 | Disclosing wifi password via content provider injection in Xiaomi |
Content provider injection
Vulnerable Android content provider
Android |
Xiaomi |
Vishwaraj Bhattrai (@vishwaraj101) |
Bug Bounty | 2020-08-16 | 2023-06-13 |
3185 | Oversecured automatically discovers persistent code execution in the Google Play Core Library |
Arbitrary Code Execution
Android |
Google |
Oversecured (@OversecuredInc) |
Bug Bounty | 2020-08-28 | 2023-06-13 |
3170 | From Android Static Analysis to RCE on Prod |
RCE
Directory listing
Missing authentication |
NA |
Aditya Dixit (@zombie007o) |
Bug Bounty | 2020-09-07 | 2023-06-13 |
3165 | Universal XSS in Android WebView (CVE-2020-6506) |
Universal XSS |
Google
Microsoft
Twitter |
Alesandro Ortiz (@AlesandroOrtizR) |
Bug Bounty | 2020-09-10 | 2023-06-13 |
3159 | Firefox for Android: LAN Based Intent Triggering |
Insecure intent
Android |
Mozilla |
initstring (@init_string) |
Bug Bounty | 2020-09-15 | 2023-06-13 |
3122 | Arbitrary code execution on Facebook for Android through download feature |
Arbitrary code execution |
Meta / Facebook |
Sayed Abdelhafiz (@dPhoeniixx) |
Bug Bounty | 2020-10-02 | 2023-06-13 |
3090 | Multiple Address Bar Spoofing Vulnerabilities In Mobile Browsers |
Authentication bypass
JWT
Android |
NHS COVID-19 App |
James Sanderson (@zofrex) |
Bug Bounty | 2020-10-20 | 2023-06-13 |
3067 | Ability To Backdoor Facebook For Android |
Insecure deeplink
Android |
Meta / Facebook |
Ashley King (@AshleyKingUK) |
Bug Bounty | 2020-10-30 | 2023-06-13 |