AES key from iOS binary decrypts 10 API secrets. Forged Apple Wallet loyalty passes for any customer.
Mar 21, 2026Non-atomic refund API allowed gift card balance multiplication. Reproduced 4/4 on production.
Mar 16, 2026API key in APK granted access to police check verification. Full name, DOB, address, criminal history downloadable.
Mar 5, 2026Unvalidated deep link parameter loaded attacker page with full transaction signing bridge access.
Mar 5, 2026Unauthenticated database function returned invoices from other organizations including payment links.
Mar 5, 2026Deterministic encryption + exported activity. Forged push notification steals session tokens without any user interaction.
Mar 4, 2026SDK key from APK created unlimited verified deep links. Chained with unfiltered WebView for in-app credential theft.
Mar 4, 2026Three chained flaws in a crypto exchange's Android app gave full account access from a single tap.
Mar 2, 2026No-auth endpoint generated support tokens for any user. Read conversations, download KYC docs, send messages as victim.
Mar 2, 2026RSA-2048 key extracted from a .so file in 5 seconds. Forged push notifications to any wallet user.
Feb 26, 2026