payload-delivery

2 articles
sort: new top best
clear filter
0 2/10

A researcher discovered a DoS vulnerability in WhatsApp for Android/iOS/Web where a malicious payload embedded in a contact file could crash the victim's phone upon delivery. The vulnerability was patched by Facebook/WhatsApp after ~2 months, and the researcher received a $500 bounty.

WhatsApp Facebook Google Pratheesh P Narayanan Android iOS
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details
0 6/10

A self-XSS vulnerability in an application form was escalated to persistent XSS through clickjacking exploitation, leveraging the absence of X-Frame-Options headers to trick users into executing malicious JavaScript via an invisible iframe overlay.

HackerOne Arbaz Hussain
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details