⤷ Title: Deep Link Hijacking leads to Account Takeover
════════════════════════
𐀪 Author: Rawan Saeed
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 14:36:48 GMT
════════════════════════
⌗ Tags: #deeplink #bug_bounty #cybersecurity #android_security #penetration_testing
════════════════════════
𐀪 Author: Rawan Saeed
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 14:36:48 GMT
════════════════════════
⌗ Tags: #deeplink #bug_bounty #cybersecurity #android_security #penetration_testing
Medium
Deep Link Hijacking leads to Account Takeover
Deep links are widely used in mobile applications to improve the user experience by opening specific pages directly inside the app…
⤷ Title: 1-Click Account Takeover via Misconfigured WebView
════════════════════════
𐀪 Author: abdelnasser
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 10:35:55 GMT
════════════════════════
⌗ Tags: #bug_bounty #android_pentesting #android_security #pentesting #webview
════════════════════════
𐀪 Author: abdelnasser
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 10:35:55 GMT
════════════════════════
⌗ Tags: #bug_bounty #android_pentesting #android_security #pentesting #webview
Medium
One Click Account Takeover via Misconfigured WebView
TL;DR: A retail Android app had a WebView exposed via deep link. JS was enabled, the url parameter accepted any scheme including…
⤷ Title: Account Takeover via Misconfigured OAuth in Android
════════════════════════
𐀪 Author: abdelnasser
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 13:04:55 GMT
════════════════════════
⌗ Tags: #penetration_testing #android_security #bug_bounty #oauth #mobile_security
════════════════════════
𐀪 Author: abdelnasser
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 13:04:55 GMT
════════════════════════
⌗ Tags: #penetration_testing #android_security #bug_bounty #oauth #mobile_security
Medium
Account Takeover via Misconfigured OAuth in Android
TL;DR: Two Android apps using Auth0 left redirect URIs in their allowlist that nothing on Android actually owned. PKCE wasn’t enforced…
⤷ Title: One Click Account Takeover via Misconfigured WebView
════════════════════════
𐀪 Author: abdelnasser
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 10:35:55 GMT
════════════════════════
⌗ Tags: #bug_bounty #android_pentesting #android_security #pentesting #webview
════════════════════════
𐀪 Author: abdelnasser
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 10:35:55 GMT
════════════════════════
⌗ Tags: #bug_bounty #android_pentesting #android_security #pentesting #webview
Medium
One Click Account Takeover via Misconfigured WebView
TL;DR: A retail Android app had a WebView exposed via deep link. JS was enabled, the url parameter accepted any scheme including…
⤷ Title: IonStack: Android 17 Two-Bug Chain Disclosed by Nebula Security
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 10 Jul 2026 14:00:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #Android 17 #Android Security #Firefox vulnerability #IonStack #Linux Kernel Flaw #Nebula Security #Responsible Disclosure
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 10 Jul 2026 14:00:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #Android 17 #Android Security #Firefox vulnerability #IonStack #Linux Kernel Flaw #Nebula Security #Responsible Disclosure
Information Security News
IonStack: Android 17 Two-Bug Chain Disclosed by Nebula Security
A security research firm has disclosed a two-vulnerability exploit chain named IonStack that affects Android 17. Nebula Security identified both vulnerabilities and has already notified the releva…
⤷ Title: Android Pentesting On A Low-Spec PC — My Setup And What Works For Me
════════════════════════
𐀪 Author: Ashish Rohra
════════════════════════
ⴵ Time: Tue, 14 Jul 2026 13:56:00 GMT
════════════════════════
⌗ Tags: #android_apps #bug_bounty #android_pentesting #android_security #android_app_development
════════════════════════
𐀪 Author: Ashish Rohra
════════════════════════
ⴵ Time: Tue, 14 Jul 2026 13:56:00 GMT
════════════════════════
⌗ Tags: #android_apps #bug_bounty #android_pentesting #android_security #android_app_development
Medium
Android Pentesting On A Low-Spec PC — My Setup And What Works For Me
Every guide out there tells you need 16 gigs of RAM, a dedicated GPU, and preferably a laptop that costs more than your rent. I have an…
⤷ Title: Android Ransomware: When Storage Access Meets Disaster
════════════════════════
𐀪 Author: Jackson F. de A. M.
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 21:43:31 GMT
════════════════════════
⌗ Tags: #infosec #kotlin #android_security
════════════════════════
𐀪 Author: Jackson F. de A. M.
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 21:43:31 GMT
════════════════════════
⌗ Tags: #infosec #kotlin #android_security
Medium
Android Ransomware: When Storage Access Meets Disaster
You already know the Android permission model is broken. You probably joke about it. What you might not realise is that it’s not just…
⤷ Title: Google Weighs Restricting Local ADB, Threatening Shizuku on Android
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sun, 26 Jul 2026 07:16:12 +0000
════════════════════════
⌗ Tags: #Android #android #Android Debug Bridge #Android security #Local ADB #Shizuku
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sun, 26 Jul 2026 07:16:12 +0000
════════════════════════
⌗ Tags: #Android #android #Android Debug Bridge #Android security #Local ADB #Shizuku
Daily CyberSecurity
Google Weighs Restricting Local ADB, Threatening Shizuku on Android
A developer recently spotted a notable proposal. Google engineers want to curb a potential security flaw in the Android Debug Bridge, or ADB. To do so, they suggest restricting local ADB connectio…
⤷ Title: How I Bypassed APK Signature Verification in an Android Application(And Why Client-Side Integrity…
════════════════════════
𐀪 Author: Iamshivamdwivedi
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 05:53:04 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #android_security #reverse_engineering #penetration_testing
════════════════════════
𐀪 Author: Iamshivamdwivedi
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 05:53:04 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #android_security #reverse_engineering #penetration_testing
Medium
How I Bypassed APK Signature Verification in an Android Application(And Why Client-Side Integrity Checks Are Not Enough)
APK signature verification is commonly implemented in Android applications to detect tampering and ensure that only the original…
⤷ Title: Google Proposes Android Local ADB Restrictions Threatening Shizuku
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 28 Jul 2026 07:18:21 +0000
════════════════════════
⌗ Tags: #Android #adb #Android Security #cybersecurity #Shizuku
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 28 Jul 2026 07:18:21 +0000
════════════════════════
⌗ Tags: #Android #adb #Android Security #cybersecurity #Shizuku
Information Security News
Google Proposes Android Local ADB Restrictions Threatening Shizuku
Android’s crowning convenience for power users may soon vanish as Google endeavors to fortify system security. Company engineers have proposed prohibiting devices from connecting to their in…
⤷ Title: Breaking Android Apps on Purpose: A SAST & DAST Walkthrough of DIVA-beta, InsecureBankv2, and…
════════════════════════
𐀪 Author: Mubbashir Khan Israil Khan Pathan
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 04:52:29 GMT
════════════════════════
⌗ Tags: #penetration_testing #android_security #owasp #mobile_pentesting #cybersecurity
════════════════════════
𐀪 Author: Mubbashir Khan Israil Khan Pathan
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 04:52:29 GMT
════════════════════════
⌗ Tags: #penetration_testing #android_security #owasp #mobile_pentesting #cybersecurity
Medium
Breaking Android Apps on Purpose: A SAST & DAST Walkthrough of DIVA-beta, InsecureBankv2, and AndroGoat
17 findings, 2 Critical, and one recurring lesson: the mobile client is never a safe place to trust
⤷ Title: Zero-Click File Drop Hits Xiaomi ShareMe: PoC Public
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 12:44:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Android security #Bluetooth LE #MiDrop #ShareMe #Xiaomi #Zero_Click
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 12:44:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Android security #Bluetooth LE #MiDrop #ShareMe #Xiaomi #Zero_Click
Daily CyberSecurity
Zero-Click File Drop Hits Xiaomi ShareMe: PoC Public
TL;DR A researcher at ByteriaLab found a zero-click flaw in Xiaomi ShareMe, also shipped as MiDrop. An attacker within Bluetooth LE range can write arbitrary files to a victim’s phone the mo…