Dark C0d3rs

Full Version: HackerOne Disclosed Reports - 2025-11-11
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Logo
High
resolved

Two click Account Takeover


Bug reported by Franc Vian was disclosed at November 11, 2025, 9:14 am   |   Deserialization of Untrusted Data

A vulnerability was discovered in the HEY Email Android application that allowed for a two-click account takeover. Improper handling of incoming deeplinks led to the application's authorization bearer token being sent to an attacker-controlled server if the user could be tricked into clicking a link and then performing an Undo action.