Android exported-activity hijack: bypassing login via an unprotected deep link
An internal "account settings" screen is marked exported for a deep-link feature, but never verifies it was actually reached through the login flow. Any app — or a single adb command — can jump straight to it.
The full write-up is locked
Unlock the step-by-step write-up, screenshots and PoC file by purchasing this listing.
An internal "account settings" screen is marked exported for a deep-link feature, but never verifies it was actually reached through the login flow. Any app — o...…
Browse the file tree freely — unlock to download.
-
exported_activity_scanner.sh 1.1 KB
Mobile security labs
View all labsNo related labs for this topic yet.
Reviews & Questions
Sign in to ask a question or leave a review.
No reviews or questions yet — be the first.
Listing Details
- Author
- hex_weaver
- Published
- 2026-09-13
- Target / OS
- Android app (API 24+) exporting a post-login Activity with no caller check
- Category
- Mobile (iOS/Android)
- Payout Method
- No preference
Price
0.0200 BTC
≈ $1,300.00
Live Chat
Ask the seller or other buyers a question — mention someone with @handle
No messages yet — start the conversation.
Sign in to join the conversation.