Android Security & Malware
43.4K subscribers
127 photos
20 videos
7 files
2.7K links
Mobile cybersecurity channel
Links: https://linktr.ee/mobilehacker
Contact: [email protected]
Download Telegram
GPUAF Using a general GPU exploit tech to attack Pixel 8
We developed an advanced exploit technique capable of transforming a conventional out-of-bounds (OOB) bug into a more potent exploit primitive, specifically a page Use-After-Free (UAF). Utilizing this technique, we successfully exploited a vulnerability in the Pixel series, achieving Kernel Code Execution.
https://www.youtube.com/watch?v=Mw6iCqjOV9Q
๐Ÿ”ฅ14๐ŸŒš3
How to intercepting Android at runtime on non-rooted devices using frida-gadget
https://dispatchersdotplayground.hashnode.dev/intercepting-android-at-runtime-on-non-rooted-devices
๐Ÿ”ฅ10๐Ÿ‘2๐ŸŒš2
[$12000] How I found 3 Critical 0-click TikTok Account Takeover Vulnerabilities, 2FA bypass & more security issues in TikTokโ€™s system
https://vojtechcekal.medium.com/12000-3-critical-0-click-tiktok-account-takeover-vulnerabilities-2fa-bypass-more-security-78554827cfc3
๐Ÿ‘20๐ŸŒš7
Wild vulnerabilities discovered in mobile dating app - Feeld with 1 Million installs on Google Play
-Disclosure of profile information to non-premium users
-Read other peopleโ€™s messages
-access to other peopleโ€™s photos & videos from their chats
-delete, recover and edit other peopleโ€™s messages
-Update someone elseโ€™s profile information
-Send messages in other peopleโ€™s chat
-Get a โ€˜Likeโ€™ from any user profile
https://fortbridge.co.uk/research/feeld-dating-app-nudes-data-publicly-available/
๐Ÿ”ฅ9๐ŸŒš5๐Ÿคฃ5๐Ÿ‘4โค1๐Ÿคฎ1
0-Click exploit discovered in MediaTek Wi-Fi chipsets affects routers and smartphones (CVE-2024-20017).
Published PoC can be tested even from a smartphone
Technical details: https://blog.coffinsec.com/0day/2024/08/30/exploiting-CVE-2024-20017-four-different-ways.html
PoC: https://github.com/mellow-hype/cve-2024-20017
๐ŸŒš11๐Ÿคฃ4โค2๐Ÿ’ฉ2๐Ÿคฎ1
Undetected Android Spyware Targeting Individuals In South Korea
https://cyble.com/blog/undetected-android-spyware-targeting-individuals-in-south-korea/
๐Ÿ”ฅ12๐Ÿฅฑ4๐Ÿค”3๐Ÿ˜ด2๐Ÿ‘1๐ŸŒš1