WhatsApp’s Task Hijacking Bug Explained

Around a year ago, I discovered a long-standing vulnerability in WhatsApp and other popular Android applications. Despite its existence for years, this vulnerability remained largely theoretical. To demonstrate its real-world impact, I successfully exploited it on WhatsApp, Facebook, and Facebook Lite. I promptly reported my findings to Facebook’s White Hat program. In this post, I’ll share […]

September 11, 2023
Read More >>

Hack The Box: Pikatwoo Machine Walkthrough – Insane Difficulty

In this post, I would like to share a walkthrough of the Pikatwoo Machine from Hack the Box. This room will be considered an Insane machine on Hack the Box What will you gain from the Pikatwoo machine? For the user flag, you will need to find an Android Application file that provides some useful information. […]

The post Hack The Box: Pikatwoo Machine Walkthrough – Insane Difficulty appeared first on Threatninja.net.

September 9, 2023
Read More >>

Google addressed an actively exploited zero-day in Android

Google released September 2023 Android security updates to address multiple flaws, including an actively exploited zero-day. Google released September 2023 Android security updates that address tens of vulnerabilities, including a zero-day flaw tracked as CVE-2023-35674 that was actively exploited in the wild. This high-severity vulnerability CVE-2023-35674 resides in the Framework component, a threat actor could […]

The post Google addressed an actively exploited zero-day in Android appeared first on Security Affairs.

September 6, 2023
Read More >>