I just love exploring security vulnerabilities and hacking things.
Security Researcher |
I just love exploring security vulnerabilities and hacking things.
Security Researcher |
The Bing Android application allows attacker-controlled URLs to be loaded via a deeplink into a WebView that exposes a JavaScript bridge to the loaded page.
A flaw in the Redacted app鈥檚 Scam Shield allows external Intents to trigger fake phishing alerts, letting malicious application or crafted deeplinks falsely flag legitimate sender IDs or phone numbers.
A DOM-based Cross-Site Scripting (XSS) vulnerability was discovered in Xiaomi Browser鈥檚 Read Mode due to insufficient sanitization of the HTML tag, allowing arbitrary HTML or JavaScript to be executed via innerHTML.
An open redirect vulnerability was discovered in Facebook鈥檚 Privacy Checkup endpoint due to the ?back_uri= parameter being processed without any security filtering, allowing attackers to redirect users to malicious website.
A persistent open redirect vulnerability was discovered in Facebook鈥檚 Push Notification endpoint due to improper validation of the ?ref= parameter, allowing attackers to redirect users to malicious sites and potentially facilitate phishing attacks.
A reflected Cross-Site Scripting (XSS) vulnerability was discovered in Opera Browser for Android鈥檚 Reader Mode due to insufficient sanitization of the HTML tag, allowing attackers to execute arbitrary JavaScript, steal sensitive data, or inject malicious content