2138 | Exploiting Request forgery on Mobile Applications. |
CSRF
Account takeover
Android
iOS |
Pinterest |
Sayed Abdelhafiz (@dPhoeniixx) |
Bug Bounty | 2021-10-19 | 2023-06-13 |
2071 | Keybase App Vulnerability: Incomplete Cleanup of Messages In Keybase for Android/iOS, CVE-2021-34421 |
Information disclosure |
Keybase |
Olivia O’Hara (@oliviaohara) |
Bug Bounty | 2021-11-17 | 2023-06-13 |
1959 | WhatsApp for Android Retains Deleted Contacts Locally |
Privacy issue |
Meta / Facebook |
Nightwatch Cybersecurity (@nightwatchcyber) |
Bug Bounty | 2021-12-30 | 2023-06-13 |
1921 | Xiaomi Execute Arbitrary JavaScript |
XSS
HTML injection
Android |
Xiaomi |
Neil Mark Ochea (@nmochea) |
Bug Bounty | 2022-01-13 | 2023-06-13 |
1918 | RCE In Adobe Acrobat Reader For Android(CVE-2021-40724) |
RCE
Path traversal
Android |
Google
Adobe |
sunny (@hulkvision) |
Bug Bounty | 2022-01-14 | 2023-06-13 |
1912 | Write Up – Private Bug Bounty: Firebase Database Exposed By Misconfiguration – $2,000 USD |
Android
Insecure Firebase database |
NA |
Omar Espino (@omespino) |
Bug Bounty | 2022-01-17 | 2023-06-13 |
1902 | Facebook room deep linking vulnerability, allow malicious user to know the code for anyone’s meeting. |
Insecure deeplink
Android |
NA |
Quel (@RootIntrud3r) |
Bug Bounty | 2022-01-21 | 2023-06-13 |
1859 | Abusing Facebooks `Call To Action` To Launch Internal Deeplinks |
CSRF
Android
iOS |
Meta / Facebook |
Ashley King (@AshleyKingUK) |
Bug Bounty | 2022-02-02 | 2023-06-13 |
1847 | Auth Bypass in com.google.android.googlequicksearchbox |
Authentication bypass |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2022-02-06 | 2023-06-13 |
1789 | Write Up – Android Application Screen Lock Bypass Via ADB Brute Forcing |
Android
Bruteforce
Authentication bypass |
NA |
Omar Espino (@omespino) |
Bug Bounty | 2022-02-22 | 2023-06-13 |
1703 | When Equal is Not, Another WebView Takeover Story |
Android |
NA |
Dimitrios Valsamaras (@Ch0pin) |
Bug Bounty | 2022-03-22 | 2023-06-13 |
1674 | Write Up – Finapi (Open Banking API) Oauth Credentials Exposed In Plain Text In Android App |
Hardcoded credentials
Android |
NA |
Omar Espino (@omespino) |
Bug Bounty | 2022-04-01 | 2023-06-13 |
1577 | Samsung Flow - Any App Can Read The External Storage |
Android
Insecure intent |
Samsung |
Ken Gannon (@Yogehi) |
Bug Bounty | 2022-05-04 | 2023-06-13 |
1576 | Samsung Galaxy - Any App Can Install Any App In The Galaxy App Store |
Android
Insecure intent |
Samsung |
Ken Gannon (@Yogehi) |
Bug Bounty | 2022-05-04 | 2023-06-13 |
1555 | From android app to access admin dashboard |
Exposed registration page
Account takeover |
NA |
Oday Alhalabi (@OdayAlhalabi) |
Bug Bounty | 2022-05-13 | 2023-06-13 |
1552 | Impact of an Insecure DeepLink |
Insecure deeplink
Android |
CafeBazaar |
Yashar Shahinzadeh (@YShahinzadeh) |
Bug Bounty | 2022-05-16 | 2023-06-13 |
1457 | XSS Blind Stored at Asset Domain Android Apps TikTok |
Stored XSS |
TikTok |
Aidil Arief |
Bug Bounty | 2022-06-16 | 2023-06-13 |
1456 | The Android kernel mitigations obstacle race |
Memory corruption
Android |
Qualcomm |
Man Yue Mo (@mmolgtm) |
Bug Bounty | 2022-06-16 | 2023-06-13 |
1445 | Hacking into the worldwide Jacuzzi SmartTub network |
SPA
Android
JWT
Privilege escalation
Mass assignment |
Jacuzzi Group
SmartTub |
Eaton Z. (@XeEaton) |
Bug Bounty | 2022-06-20 | 2023-06-13 |
1437 | Lock Screen Bypass Exploit of Android Devices (CVE-2022–20006) |
Authentication bypass
Lock screen bypass |
Google |
Joshua Nearchos |
Bug Bounty | 2022-06-23 | 2023-06-13 |
1337 | React debug.keystore key was trusted by Meta(Facebook) which caused to Instagram account takeover by malicious apps. |
Account takeover
Android |
Meta / Facebook |
Dzmitry Lukyanenka (@vulnano) |
Bug Bounty | 2022-07-19 | 2023-06-13 |
1261 | The quantum state of Linux kernel garbage collection CVE-2021-0920 (Part I) |
Memory corruption
Race condition
Local Privilege Escalation
Android |
Linux Kernel Organization
Google
Samsung |
Xingyu Jin |
Bug Bounty | 2022-08-10 | 2023-06-13 |
1250 | Identity Confusion in WebView-based Mobile App-in-app Ecosystems |
Android
iOS |
Alipay |
Lei Zhang, Zhibo Zhang, Ancong Liu, Yinzhi Cao, Xiaohan Zhang, Yanjun Chen, Yuan Zhang, Guangliang Yang & Min Yang |
Bug Bounty | 2022-08-11 | 2023-06-13 |
1240 | Researching Xiaomi’s TEE to get to Chinese money |
Payment bypass
Android
Memory corruption |
Xiaomi |
Slava Makkaveev |
Bug Bounty | 2022-08-12 | 2023-06-13 |
1232 | How I earned a $7000 bug bounty from Grab (RCE Unique Bugs) |
RCE
Android |
Grab |
ANDRI |
Bug Bounty | 2022-08-13 | 2023-06-13 |