device-fingerprinting

1 article
sort: new top best
clear filter
0 7/10

Stored blind XSS vulnerability in Telegram iOS app allowing arbitrary HTML/JavaScript execution via unvalidated HTML files in webview, enabling device fingerprinting, user activity tracking, and IP geolocation. Successfully exploited by uploading malicious HTML file that executed JavaScript to extract navigator object data and communicate with attacker server.

Telegram WhatsApp Facebook CVE-2018-UNKNOWN omespino iPhone 6 iPhone 7 iOS 11.2.5 iOS 11.2.6 Telegram iOS 4.7.1
omespino.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details