3046 | Firefox for Android: LAN-Based Intent Triggering |
Insecure intent
Android |
Mozilla |
initstring (@init_string) |
Bug Bounty | 2020-11-10 | 2023-06-13 |
2986 | Opera Browser Cross Site Scripting (XSS) |
XSS
Android |
Opera |
Neil Mark Ochea (@nmochea) |
Bug Bounty | 2020-12-05 | 2023-06-13 |
2952 | Hack crypto secrets from heap memory to exploit Android application |
Cryptographic issues |
NA |
secureITmania (@secureitmania) |
Bug Bounty | 2020-12-22 | 2023-06-13 |
2947 | Full Address Bar Spoofing On Opera Mini Android |
Address Bar Spoofing |
Opera
Google |
Piyush Raj ~ Rex (@0x48piraj) |
Bug Bounty | 2020-12-26 | 2023-06-13 |
2887 | ShazLocate! Abusing CVE-2019-8791 & CVE-2019-8792 |
Insecure deeplink
Information disclosure
Android |
Google
Apple |
Ashley King (@AshleyKingUK) |
Bug Bounty | 2021-01-17 | 2023-06-13 |
2851 | Android apk leaks access token to takeover the whole infrastructure |
Information disclosure
Hardcoded credentials
Android |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-01-30 | 2023-06-13 |
2829 | Bigbasket Bug Bounty Writeup |
Insecure data storage
Android |
NA |
Lohith Gowda M (@lohi_gowda_) |
Bug Bounty | 2021-02-08 | 2023-06-13 |
2816 | How I was able to get extra coins |
Logic flaw
Android |
NA |
Saddam Hussain (@wisdomfreak1) |
Bug Bounty | 2021-02-12 | 2023-06-13 |
2799 | SHAREit Flaw Could Lead to Remote Code Execution |
Android
RCE
MiTM
Man-in-the-Disk attack
Insecure intent
Vulnerable Android content provider |
SHAREit |
Echo Duan |
Bug Bounty | 2021-02-15 | 2023-06-13 |
2743 | Content Injection (RCE) in Yandex Browser for Android [2018] |
MiTM |
Yandex |
Nightwatch Cybersecurity (@nightwatchcyber) |
Bug Bounty | 2021-03-03 | 2023-06-13 |
2734 | Stored XSS in Google Ads Android Application— $3133.70 |
Stored XSS
HTML injection |
Google |
Ashish Dhone (@ashketchum_16) |
Bug Bounty | 2021-03-07 | 2023-06-13 |
2706 | TikTok for Android 1-Click RCE |
RCE
XSS
Insecure intent
Android |
TikTok |
Sayed Abdelhafiz (@dPhoeniixx) |
Bug Bounty | 2021-03-18 | 2023-06-13 |
2613 | Page Owners Can’t remove or change page roles of deactivated users (or if Attacker blocks the page owner) in Facebook Lite, Facebook for Android and touch.facebook.com |
Logic flaw |
Meta / Facebook |
Baibhav Anand (@SpongeBhav) |
Bug Bounty | 2021-04-22 | 2023-06-13 |
2595 | Exploiting memory corruption vulnerabilities on Android |
Memory corruption
Android |
Paypal |
Oversecured (@OversecuredInc) |
Bug Bounty | 2021-04-30 | 2023-06-13 |
2568 | Exploiting Activity in medium android app |
Insecure intent
Android |
Medium |
Raju kumar (@MrCyberwarrior) |
Bug Bounty | 2021-05-10 | 2023-06-13 |
2543 | Time-Based SQL Injection to Dumping the Database |
SQL injection
Android |
NA |
Naveen J (@thevillagehackr) |
Bug Bounty | 2021-05-19 | 2023-06-13 |
2504 | Android: Exploring vulnerabilities in WebResourceResponse |
Arbitrary file read
Android |
Amazon |
Oversecured (@OversecuredInc) |
Bug Bounty | 2021-06-03 | 2023-06-13 |
2490 | Two weeks of securing Samsung devices: Part 1 |
Arbitrary file write
Insecure intent
Android |
Samsung |
Oversecured (@OversecuredInc) |
Bug Bounty | 2021-06-10 | 2023-06-13 |
2472 | Why dynamic code loading could be dangerous for your apps: a Google example |
Arbitrary file write
Insecure intent
Android |
Google |
Oversecured (@OversecuredInc) |
Bug Bounty | 2021-06-17 | 2023-06-13 |
2448 | Gaining access to protected components |
Vulnerable Android content provider
Android |
NA |
DavMehtab Zafar (@0xmzfr) |
Bug Bounty | 2021-06-25 | 2023-06-13 |
2399 | Hacking Xiaomi%27S Android Apps - Part 1 |
Android
Information disclosure
Open redirect
Privacy issue |
Xiaomi |
Ameya (@iamTakeMyHand) |
Bug Bounty | 2021-07-19 | 2023-06-13 |
2340 | Size Matters — CVE-2021–0485 (High) |
Local Privilege Escalation
Android |
Google |
Dimitrios Valsamaras (@Ch0pin) |
Bug Bounty | 2021-08-07 | 2023-06-13 |
2318 | Two weeks of securing Samsung devices: Part 2 |
Arbitrary file write
Arbitrary file read
Vulnerable Android content provider
Android |
Samsung |
Oversecured (@OversecuredInc) |
Bug Bounty | 2021-08-16 | 2023-06-13 |
2188 | Bypass of biometrics & password security functionality for Android |
Authentication bypass
Android |
CoinDCX |
Dheeraj Madhukar (@Dheerajmadhukar) |
Bug Bounty | 2021-09-27 | 2023-06-13 |
2157 | How I Hacked Billion Android Users Social And 3rd Party Account | A Story About 5000$ Bug |
Android |
Google |
Karthikeyan.V (@karthithehacker) |
Bug Bounty | 2021-10-10 | 2023-06-13 |