⤷ Title: I Scanned 10 Popular F-Droid Apps With My Security Scanner — Open Source ≠ Secure
════════════════════════
𐀪 Author: Yehor Mamaiev
════════════════════════
ⴵ Time: Sat, 23 May 2026 10:00:11 GMT
════════════════════════
⌗ Tags: #android_security #application_security #mobile_security #cybersecurity #open_source
════════════════════════
𐀪 Author: Yehor Mamaiev
════════════════════════
ⴵ Time: Sat, 23 May 2026 10:00:11 GMT
════════════════════════
⌗ Tags: #android_security #application_security #mobile_security #cybersecurity #open_source
Medium
I Scanned 10 Popular F-Droid Apps With My Security Scanner — Open Source ≠ Secure
“It’s open source, so it’s secure.”
⤷ Title: AndroPseudoProtect — Exploiting
════════════════════════
𐀪 Author: Mohammed Ashraf
════════════════════════
ⴵ Time: Sat, 23 May 2026 10:54:05 GMT
════════════════════════
⌗ Tags: #ctf #penetration_testing #android_security #8ksec #ctf_writeup
════════════════════════
𐀪 Author: Mohammed Ashraf
════════════════════════
ⴵ Time: Sat, 23 May 2026 10:54:05 GMT
════════════════════════
⌗ Tags: #ctf #penetration_testing #android_security #8ksec #ctf_writeup
Medium
AndroPseudoProtect — Exploiting
Step 1
⤷ Title: AndroDialer — When a Phone App Lets Anyone Make Calls For It
════════════════════════
𐀪 Author: Mohammed Ashraf
════════════════════════
ⴵ Time: Sun, 24 May 2026 12:06:51 GMT
════════════════════════
⌗ Tags: #penetration_testing #8ksec #android_security #ctf #ctf_writeup
════════════════════════
𐀪 Author: Mohammed Ashraf
════════════════════════
ⴵ Time: Sun, 24 May 2026 12:06:51 GMT
════════════════════════
⌗ Tags: #penetration_testing #8ksec #android_security #ctf #ctf_writeup
Medium
AndroDialer — When a Phone App Lets Anyone Make Calls For It
Step 1
⤷ Title: DroidCave — Stealing Passwords Through an Over-Permissive ContentProvider
════════════════════════
𐀪 Author: Mohammed Ashraf
════════════════════════
ⴵ Time: Sun, 24 May 2026 14:19:03 GMT
════════════════════════
⌗ Tags: #penetration_testing #android_security #ctf_writeup #ctf #8ksec
════════════════════════
𐀪 Author: Mohammed Ashraf
════════════════════════
ⴵ Time: Sun, 24 May 2026 14:19:03 GMT
════════════════════════
⌗ Tags: #penetration_testing #android_security #ctf_writeup #ctf #8ksec
Medium
DroidCave — Stealing Passwords Through an Over-Permissive ContentProvider
This is my writeup for the DroidCave challenge from 8kSec Android Labs. The goal is to build an app that looks completely innocent but…
⤷ Title: Android Uygulamalarında IPC ve Bileşen Güvenliği
════════════════════════
𐀪 Author: Aybora Ünveren
════════════════════════
ⴵ Time: Mon, 25 May 2026 19:00:22 GMT
════════════════════════
⌗ Tags: #android_security #penetration_testing #cybersecurity #mobile_security #bug_bounty
════════════════════════
𐀪 Author: Aybora Ünveren
════════════════════════
ⴵ Time: Mon, 25 May 2026 19:00:22 GMT
════════════════════════
⌗ Tags: #android_security #penetration_testing #cybersecurity #mobile_security #bug_bounty
Medium
Android Uygulamalarında IPC ve Bileşen Güvenliği
Bu yazımda Android uygulamalarında sıkça karşılaşılan bileşen ve IPC güvenlik zafiyetlerini ele alacağım. Bu zafiyetler; tek bir kullanıcı…
⤷ Title: How I Found a P2 Cryptographic Vulnerability in Android’s KeyManager — Google VRP
════════════════════════
𐀪 Author: Rajagiri Sai Ganesh
════════════════════════
ⴵ Time: Thu, 28 May 2026 19:55:39 GMT
════════════════════════
⌗ Tags: #android_security #java_security #bug_bounty #google_vrp #cryptography
════════════════════════
𐀪 Author: Rajagiri Sai Ganesh
════════════════════════
ⴵ Time: Thu, 28 May 2026 19:55:39 GMT
════════════════════════
⌗ Tags: #android_security #java_security #bug_bounty #google_vrp #cryptography
Medium
How I Found a P2 Cryptographic Vulnerability in Android’s KeyManager — Google VRP
Unauthorised KeyManager modification via Java reflection bypass — enabling cryptographic registry tampering inside Google’s ecosystem
⤷ Title: Android Zero-Day Flaw Exploited in the Wild: June 2026 Patches Released
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 02 Jun 2026 01:39:00 +0000
════════════════════════
⌗ Tags: #Android #Vulnerability Report #Android security #CVE_2025_48595 #Framework Vulnerability #Google Patches #zero_day #Zero_Day Exploit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 02 Jun 2026 01:39:00 +0000
════════════════════════
⌗ Tags: #Android #Vulnerability Report #Android security #CVE_2025_48595 #Framework Vulnerability #Google Patches #zero_day #Zero_Day Exploit
Daily CyberSecurity
Android Zero-Day Flaw Exploited in the Wild: June 2026 Patches Released
Google recently released a critical security patch to address a dangerous Android zero day flaw. Specifically, this emergency update arrives as part of the broader system release. Cybercriminals a…
⤷ Title: When One Line of Code Becomes a Global Risk: Lessons From a Microsoft Android App Security Exposure
════════════════════════
𐀪 Author: Jas
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 09:59:06 GMT
════════════════════════
⌗ Tags: #devsecops #mobile_security #application_security #cybersecurity #android_security
════════════════════════
𐀪 Author: Jas
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 09:59:06 GMT
════════════════════════
⌗ Tags: #devsecops #mobile_security #application_security #cybersecurity #android_security
Medium
When One Line of Code Becomes a Global Risk: Lessons From a Microsoft Android App Security Exposure
In software development, even the smallest coding oversight can have far-reaching consequences. A recently disclosed security issue…
⤷ Title: Finding an Unintended Privilege Escalation While Solving Mobile Hacking Lab’s Food Store Challenge
════════════════════════
𐀪 Author: @4b6o07
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 15:04:35 GMT
════════════════════════
⌗ Tags: #bug_bounty #reverse_engineering #android_security #mobileapplicationsecurity #cybersecurity
════════════════════════
𐀪 Author: @4b6o07
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 15:04:35 GMT
════════════════════════
⌗ Tags: #bug_bounty #reverse_engineering #android_security #mobileapplicationsecurity #cybersecurity
Medium
Finding an Unintended Privilege Escalation While Solving Mobile Hacking Lab’s Food Store Challenge
While hunting for SQL Injection, I accidentally became the CEO of the Food Store.
⤷ Title: Mastering Frida: Solving the OWASP MSTG Android Lab Challenges
════════════════════════
𐀪 Author: Basithmohammedali
════════════════════════
ⴵ Time: Thu, 04 Jun 2026 08:37:02 GMT
════════════════════════
⌗ Tags: #penetration_testing #mobile_security #owasp_top_10 #frida #android_security
════════════════════════
𐀪 Author: Basithmohammedali
════════════════════════
ⴵ Time: Thu, 04 Jun 2026 08:37:02 GMT
════════════════════════
⌗ Tags: #penetration_testing #mobile_security #owasp_top_10 #frida #android_security
Medium
Mastering Frida: Solving the OWASP MSTG Android Lab Challenges
Introduction
⤷ Title: Deep Link Hijacking leads to Account Takeover
════════════════════════
𐀪 Author: Rawan Saeed
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 14:36:48 GMT
════════════════════════
⌗ Tags: #deeplink #bug_bounty #cybersecurity #android_security #penetration_testing
════════════════════════
𐀪 Author: Rawan Saeed
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 14:36:48 GMT
════════════════════════
⌗ Tags: #deeplink #bug_bounty #cybersecurity #android_security #penetration_testing
Medium
Deep Link Hijacking leads to Account Takeover
Deep links are widely used in mobile applications to improve the user experience by opening specific pages directly inside the app…
⤷ Title: 1-Click Account Takeover via Misconfigured WebView
════════════════════════
𐀪 Author: abdelnasser
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 10:35:55 GMT
════════════════════════
⌗ Tags: #bug_bounty #android_pentesting #android_security #pentesting #webview
════════════════════════
𐀪 Author: abdelnasser
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 10:35:55 GMT
════════════════════════
⌗ Tags: #bug_bounty #android_pentesting #android_security #pentesting #webview
Medium
One Click Account Takeover via Misconfigured WebView
TL;DR: A retail Android app had a WebView exposed via deep link. JS was enabled, the url parameter accepted any scheme including…
⤷ Title: Account Takeover via Misconfigured OAuth in Android
════════════════════════
𐀪 Author: abdelnasser
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 13:04:55 GMT
════════════════════════
⌗ Tags: #penetration_testing #android_security #bug_bounty #oauth #mobile_security
════════════════════════
𐀪 Author: abdelnasser
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 13:04:55 GMT
════════════════════════
⌗ Tags: #penetration_testing #android_security #bug_bounty #oauth #mobile_security
Medium
Account Takeover via Misconfigured OAuth in Android
TL;DR: Two Android apps using Auth0 left redirect URIs in their allowlist that nothing on Android actually owned. PKCE wasn’t enforced…
⤷ Title: One Click Account Takeover via Misconfigured WebView
════════════════════════
𐀪 Author: abdelnasser
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 10:35:55 GMT
════════════════════════
⌗ Tags: #bug_bounty #android_pentesting #android_security #pentesting #webview
════════════════════════
𐀪 Author: abdelnasser
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 10:35:55 GMT
════════════════════════
⌗ Tags: #bug_bounty #android_pentesting #android_security #pentesting #webview
Medium
One Click Account Takeover via Misconfigured WebView
TL;DR: A retail Android app had a WebView exposed via deep link. JS was enabled, the url parameter accepted any scheme including…
⤷ Title: IonStack: Android 17 Two-Bug Chain Disclosed by Nebula Security
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 10 Jul 2026 14:00:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #Android 17 #Android Security #Firefox vulnerability #IonStack #Linux Kernel Flaw #Nebula Security #Responsible Disclosure
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 10 Jul 2026 14:00:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #Android 17 #Android Security #Firefox vulnerability #IonStack #Linux Kernel Flaw #Nebula Security #Responsible Disclosure
Information Security News
IonStack: Android 17 Two-Bug Chain Disclosed by Nebula Security
A security research firm has disclosed a two-vulnerability exploit chain named IonStack that affects Android 17. Nebula Security identified both vulnerabilities and has already notified the releva…
⤷ Title: Android Pentesting On A Low-Spec PC — My Setup And What Works For Me
════════════════════════
𐀪 Author: Ashish Rohra
════════════════════════
ⴵ Time: Tue, 14 Jul 2026 13:56:00 GMT
════════════════════════
⌗ Tags: #android_apps #bug_bounty #android_pentesting #android_security #android_app_development
════════════════════════
𐀪 Author: Ashish Rohra
════════════════════════
ⴵ Time: Tue, 14 Jul 2026 13:56:00 GMT
════════════════════════
⌗ Tags: #android_apps #bug_bounty #android_pentesting #android_security #android_app_development
Medium
Android Pentesting On A Low-Spec PC — My Setup And What Works For Me
Every guide out there tells you need 16 gigs of RAM, a dedicated GPU, and preferably a laptop that costs more than your rent. I have an…