I just love exploring security vulnerabilities and hacking things.
Security Researcher @mobilehackinglab
I just love exploring security vulnerabilities and hacking things.
Security Researcher @mobilehackinglab
A DOM-based Cross-Site Scripting (XSS) vulnerability was discovered in Xiaomi Browser鈥檚 Read Mode due to insufficient sanitization of the HTML tag, allowing arbitrary HTML or JavaScript to be executed via innerHTML.
An open redirect vulnerability was discovered in Facebook鈥檚 Privacy Checkup endpoint due to the ?back_uri= parameter being processed without any security filtering, allowing attackers to redirect users to malicious website.
A persistent open redirect vulnerability was discovered in Facebook鈥檚 Push Notification endpoint due to improper validation of the ?ref= parameter, allowing attackers to redirect users to malicious sites and potentially facilitate phishing attacks.
A reflected Cross-Site Scripting (XSS) vulnerability was discovered in Opera Browser for Android鈥檚 Reader Mode due to insufficient sanitization of the HTML tag, allowing attackers to execute arbitrary JavaScript, steal sensitive data, or inject malicious content