From Signal to the Android SDK: Chaining Path Traversal, Mimetype Confusion, Security Check Bypass and File Descriptor Bruteforce for Arbitrary File Access
https://blog.ostorlab.co/signal-arbitrary-file-read.html
Post #2629
6.28K
Forwarded from The Bug Bounty Hunter
blog.ostorlab.co Ostorlab: Mobile App Security Testing for Android and iOS This technical analysis reveals how sophisticated attack chains—combining path traversal, symbolic link manipulation, and Android SDK quirks—can breach Signal Android's defenses to extract sensitive internal files, despite its legendary encryption remaining…- 👍 13
- ❤ 7