Dark C0d3rs
HackerOne Disclosed Reports - 2026-01-16 - Printable Version

+- Dark C0d3rs (https://darkcoders.wiki)
+-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log)
+--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports)
+--- Thread: HackerOne Disclosed Reports - 2026-01-16 (/Thread-HackerOne-Disclosed-Reports-2026-01-16)



HackerOne disclosed reports - 2026-01-16 - hashXploiter - 01-17-2026

Logo
Low
resolved

Can download files on Android app without permission


Bug reported by hakuna was disclosed at January 16, 2026, 8:53 pm   |   Improper Access Control - Generic

A vulnerability was discovered in the Android app where users could download files shared with them, even if the owner had disabled the download option. The vulnerability affected various file types, including PDF, document, image, and presentation files. The vulnerability allowed users to access and download the shared files without the owner's permission.