HackerOne Disclosed Reports - 2025-11-11

0 Replies, 115 Views

Logo
High
resolved

Two click Account Takeover


Bug reported by Franc Vian was disclosed at November 11, 2025, 9:14 am   |   Deserialization of Untrusted Data

A vulnerability was discovered in the HEY Email Android application that allowed for a two-click account takeover. Improper handling of incoming deeplinks led to the application's authorization bearer token being sent to an attacker-controlled server if the user could be tricked into clicking a link and then performing an Undo action.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]

Messages In This Thread
HackerOne disclosed reports - 2025-11-11 - by hashXploiter - 11-12-2025, 12:30 PM



Users browsing this thread: 1 Guest(s)