Android 18
- Access Twitter blue features using deeplink without a subscription.
- Instagram vulnerability : Turn off all type of message requests using deeplink (Android)
- Facebook android vulnerability: Launching internal/tighten deeplink onbehalf of user
- Facebook android webview vulnerability : Execute arbitrary javascript (xss) and load arbitrary website
- [IDOR] add or remove the linked publications from Author Publisher settings — Facebook Bug Bounty
- Cisco Webex Teams Mobile (Android) Information Disclosure Vulnerability
- Crash Instagram Bug (Android) using U+043E (Unpatched)
- Facebook Messenger for android indirect thread deletion vulnerability.
- Google Photos : Theft of Database & Arbitrary Files Android Vulnerability
- Sending ephemeral message – disposable message to any Facebook user
- Facebook: Linkshim protection bypass using fb://webview
- Perform substring search for emails even if Workplace admin hides email profile field.
- Bypass Samsung Knox protection to read files stored in a secure folder | Android
- Xiaomi Android : Harvest private/system files (Updated POC)
- Information disclosure through javascript bridge in Android
- DoS on Facebook Android using 65530 chars of ZERO WIDTH NO-BREAK SPACE.
- Twitter Android Javascript Interface Vulnerability
- From NA to $3000 : Facebook’s URL spoofing vulnerability