![]() |
|
HackerOne Disclosed Reports - 2026-08-13 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2026-08-13 (/Thread-HackerOne-Disclosed-Reports-2026-08-13) |
HackerOne disclosed reports - 2026-08-13 - hashXploiter - 08-14-2026
Low
resolved Debug Deep Link Abuse Allows Repeated Forced Logout and Application DisruptionBug reported by Karim Mohamed was disclosed at August 13, 2026, 1:30 pm | Violation of Secure Design Principles A debug deep link was discovered in the Android application "com.yelp.android.biz" that could be triggered externally, causing the application to crash and the user's session to be invalidated, requiring the user to log in again. The existence of this exposed deep link allowed any malicious application installed on the same device to repeatedly trigger this behavior, resulting in a persistent local denial of service against the application. |