Android Security & Malware
43.5K subscribers
130 photos
20 videos
7 files
2.71K links
Mobile cybersecurity channel
Links: https://linktr.ee/mobilehacker
Contact: mobilehackerofficial@gmail.com
Download Telegram
Intercepting iHealth app traffic with Caido and Frida
iHealth Nexus Pro Body Composition Scale only communicates via Bluetooth Low Energy (BLE) to a iHealth mobile app
Blog: https://brownfinesecurity.com/blog/intercepting-mobile-traffic-with-caido-and-frida/
Video: https://youtu.be/GvRi7chKMPI
๐Ÿ”ฅ10๐Ÿ‘4
GPUAF Using a general GPU exploit tech to attack Pixel 8
We developed an advanced exploit technique capable of transforming a conventional out-of-bounds (OOB) bug into a more potent exploit primitive, specifically a page Use-After-Free (UAF). Utilizing this technique, we successfully exploited a vulnerability in the Pixel series, achieving Kernel Code Execution.
https://www.youtube.com/watch?v=Mw6iCqjOV9Q
๐Ÿ”ฅ14๐ŸŒš3
How to intercepting Android at runtime on non-rooted devices using frida-gadget
https://dispatchersdotplayground.hashnode.dev/intercepting-android-at-runtime-on-non-rooted-devices
๐Ÿ”ฅ10๐Ÿ‘2๐ŸŒš2
[$12000] How I found 3 Critical 0-click TikTok Account Takeover Vulnerabilities, 2FA bypass & more security issues in TikTokโ€™s system
https://vojtechcekal.medium.com/12000-3-critical-0-click-tiktok-account-takeover-vulnerabilities-2fa-bypass-more-security-78554827cfc3
๐Ÿ‘20๐ŸŒš7
Android Vo1d malware infected over a million Android TV boxes
It is a backdoor that puts its components in the system storage and, when commanded by attackers, is capable of secretly downloading and installing third-party software
https://news.drweb.com/show/?i=14900&lng=en
๐Ÿ‘8๐ŸŒš3๐Ÿ‘1
Wild vulnerabilities discovered in mobile dating app - Feeld with 1 Million installs on Google Play
-Disclosure of profile information to non-premium users
-Read other peopleโ€™s messages
-access to other peopleโ€™s photos & videos from their chats
-delete, recover and edit other peopleโ€™s messages
-Update someone elseโ€™s profile information
-Send messages in other peopleโ€™s chat
-Get a โ€˜Likeโ€™ from any user profile
https://fortbridge.co.uk/research/feeld-dating-app-nudes-data-publicly-available/
๐Ÿ”ฅ9๐ŸŒš5๐Ÿคฃ5๐Ÿ‘4โค1๐Ÿคฎ1