Client-Side SSRF to Credential Theft via Exported Android Activity
How reading one exported Activity by hand, following an unvalidated URL field, and misreading the impact twice led to a one-tap session t...
Tag
How reading one exported Activity by hand, following an unvalidated URL field, and misreading the impact twice led to a one-tap session t...
A clean reflected XSS on an auth-less subdomain that topped out at alert(1), and the investigation that turned it into a critical account...