HackerOne Disclosed Reports - 2026-08-13

0 Replies, 7 Views

Logo
Low
resolved

Debug Deep Link Abuse Allows Repeated Forced Logout and Application Disruption


Bug reported by Karim Mohamed was disclosed at August 13, 2026, 1:30 pm   |   Violation of Secure Design Principles

A debug deep link was discovered in the Android application "com.yelp.android.biz" that could be triggered externally, causing the application to crash and the user's session to be invalidated, requiring the user to log in again. The existence of this exposed deep link allowed any malicious application installed on the same device to repeatedly trigger this behavior, resulting in a persistent local denial of service against the application.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)