Security

  • How a Misconfigured Android SDK Can Lead to Stealthy Camera Abuse

    ·

    During a security assessment of a popular Android application, I discovered a serious vulnerability resulting from a misconfigured third-party SDK. This vulnerability allowed an arbitrary third-party application to launch an exported activity in the target app and use the app’s granted camera permission for stealthy photo capture—without any user interaction. Vulnerability Overview The vulnerable SDK…

    Read More

  • Unveiling the Secrets: SSRF Adventures in Microsoft’s AI Playground

    ·

    As-salamu alaykum everyone, I will discuss a comprehensive SSRF (Server-Side Request Forgery) exploit that 5h3rl0ck and I discovered and successfully exploited within one of Microsoft’s AI products, namely Microsoft Designer. Microsoft Designer is an AI-powered graphic design app that helps you create stunning social media posts, invitations, digital postcards, graphics, and more, all in a flash. While…

    Read More