TGViewer
Android Security & Malware Android Security & Malware @androidmalware · 44.7K subscribers
Post #2190 10.2K
SSRF in Mobile Security Framework (MobSF) version 3.9.5 Beta and prior (CVE-2024-29190)
MobSF does not perform any input validation when extracting the hostnames in android:host, so requests can also be sent to local hostnames. This can lead to server-side request forgery (SSRF). An attacker can cause the server to make a connection to internal-only services within the organization's infrastructure
https://github.com/MobSF/Mobile-Security-Framework-MobSF/security/advisories/GHSA-wfgj-wrgh-h3r3
GitHub SSRF Vulnerability on assetlinks_check(act_name, well_knowns) ### Summary While examining the "App Link assetlinks.json file could not be found" vulnerability detected by MobSF, we, as the Trendyol Application Security team, noticed that a GET requ...
  • 👍 9
  • ❤ 1
More from @androidmalware
  1. Oct 7, 2026CVE-2026-23866: Finding a Whatsapp NDay https://numb3rs.re/posts/cve-2026-23866-finding-a-…
  2. Oct 1, 2026CVE-2026-86950: The Great Glyph Grift An in-the-wild iOS bug with a possible WhatsApp zero…
  3. Sep 29, 2026CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF — iOS/macOS kernel vulnerability…
  4. Sep 29, 2026How we found 24 Android vulnerabilities using our open source AI security agent https://gi…
  5. Sep 29, 2026From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat https://www.cl…
  6. Sep 28, 2026apk-reverse: An Agent Skill for Android APK reverse engineering, debloating, ad removal, s…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →