1201 | Amazon Quickly Fixed A Vulnerability In Ring Android App That Could Expose Users’ Camera Recordings |
XSS
iOS
Android |
Amazon |
David Sopas (@dsopas) |
Bug Bounty | 2022-08-18 | 2023-06-13 |
1177 | Chaining Telegram bugs to steal session-related files. |
Arbitrary file read
Android |
Telegram |
Sayed Abdelhafiz (@dPhoeniixx) |
Bug Bounty | 2022-08-25 | 2023-06-13 |
1149 | Vulnerability in TikTok Android app could lead to one-click account hijacking |
Insecure deeplink
Android |
TikTok |
Microsoft 365 Defender Research Team |
Bug Bounty | 2022-08-31 | 2023-06-13 |
1093 | Contentful Access Token Disclosure in Android APK |
Information disclosure
Android |
NA |
Cyberali |
Bug Bounty | 2022-09-12 | 2023-06-13 |
1083 | Attacking the Android kernel using the Qualcomm TrustZone |
Memory corruption |
Qalcomm
Google |
Tamir Zahavi-Brunner (@tamir_zb) |
Bug Bounty | 2022-09-14 | 2023-06-13 |
1067 | Android Application Forgot Password Token Leakage Leading to Account Takeover |
Information disclosure
Password reset
Account takeover
Android |
NA |
Cyberali |
Bug Bounty | 2022-09-19 | 2023-06-13 |
1043 | Arbitrary File Corruption: End - to - End Encrypted Messaging Application |
Insecure intent
Android |
NA |
Neil Mark Ochea (@nmochea) |
Bug Bounty | 2022-09-23 | 2023-06-13 |
1034 | Shopping App Deeplink Arbitrary URLs |
Insecure deeplink
Android |
NA |
Neil Mark Ochea (@nmochea) |
Bug Bounty | 2022-09-25 | 2023-06-13 |
1026 | From nothing to AWS credentials |
SSRF |
NA |
(@darkandroider) |
Bug Bounty | 2022-09-27 | 2023-06-13 |
983 | Gcash Vulnerability Walkthrough |
Android
Insecure deeplink
Insecure intent |
Gcash |
Neil Mark Ochea (@nmochea) |
Bug Bounty | 2022-10-10 | 2023-06-13 |
980 | [Hacking Banks] Broken Access Control Vulnerability in Banking application [PART I] |
Broken Access Control
Android |
NA |
Abdelhak Kharroubi |
Bug Bounty | 2022-10-10 | 2023-06-13 |
937 | Scan QR Code and Got Hacked (CVE-2021–43530 : UXSS on Firefox Android Version) |
Universal XSS
Android |
Mozilla |
hafiizh |
Bug Bounty | 2022-10-19 | 2023-06-13 |
846 | Accidental $70k Google Pixel Lock Screen Bypass |
Lock screen bypass
Authentication bypass
Android |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2022-11-10 | 2023-06-13 |
843 | Discovering vendor-specific vulnerabilities in Android |
Android |
Samsung
Google |
Oversecured (@OversecuredInc) |
Bug Bounty | 2022-11-10 | 2023-06-13 |
801 | Hacking Smartwatches for Spear Phishing |
IoT
Phishing
Android |
NA |
Cybervelia (@cybervelia) |
Bug Bounty | 2022-11-20 | 2023-06-13 |
787 | Account Takeover in KAYAK |
Account takeover
Android
Insecure deeplink |
KAYAK |
Carlos Bello |
Bug Bounty | 2022-11-23 | 2023-06-13 |
773 | WebView XSS, account takeover |
Webview XSS
Android
Account takeover
Improper Export of Android Application Components |
NA |
shafou |
Bug Bounty | 2022-11-26 | 2023-06-13 |
771 | [Hacking Bank] The Second Story of Finding Critical Vulnerabilities on Banking Application |
Android
Hardcoded credentials
IDOR |
NA |
Abdelhak Kharroubi |
Bug Bounty | 2022-11-26 | 2023-06-13 |
769 | Automating Unsolicited Richard Pics; Pwning 60,000 Digital Picture Frames |
IDOR
Broken Access Control
Android
IoT |
Ourphoto |
Nick M (@1oopho1e) |
Bug Bounty | 2022-11-26 | 2023-06-13 |
764 | Multiple Vulnerabilities found in Airtel Android Application |
Arbitrary Code Execution
URL validation bypass
Symlink attack
XSS
Android
Webview |
Airtel
Google |
Gaurang Bhatnagar (@hax0rgb) |
Bug Bounty | 2022-11-27 | 2023-06-13 |
734 | Manipulating AES Traffic using a Chain of Proxies and Hardcoded Keys |
Android
Hardcoded credentials
Client-side encryption bypass |
NA |
Aditya Dixit (@zombie007o) |
Bug Bounty | 2022-12-03 | 2023-06-13 |
713 | Public Report – VPN by Google One Security Assessment |
Android
iOS
DoS
Windows
MacoS
Local Privilege Escalation |
Google |
Daniel Romero (@daniel_rome) |
Bug Bounty | 2022-12-09 | 2023-06-13 |
664 | 0 click Facebook Account Takeover and Two-Factor Authentication Bypass |
Authentication bypass
GraphQL
Account takeover
Android
MFA bypass |
Meta / Facebook |
abdellah yaala (@yaalaab) |
Bug Bounty | 2022-12-21 | 2023-06-13 |
563 | Technical Advisory – Multiple Vulnerabilities in the Galaxy App Store (CVE-2023-21433, CVE-2023-21434) |
Android
Insecure intent
Insecure deeplink
URL validation bypass |
Samsung |
Ken Gannon (@Yogehi) |
Bug Bounty | 2023-01-20 | 2023-06-13 |
539 | How I Found My First Bug in Android App |
Android
Authentication bypass
Insecure intent |
NA |
Barath Stalin |
Bug Bounty | 2023-01-26 | 2023-06-13 |