232 Followers
147 Following
5 Posts
Bugs are my friends. Shell smuggling business in the past. I once had a Pwnie. Hacking all the things at Interrupt Labs.

Chrome decided to derestrict an interesting bug from @jann from 7 years ago. Android applications with the READ_EXTERNAL_STORAGE permission were able to steal CSRF tokens by forcing the browser to save arbitrary web pages to disk and then read these files from the Downloads folder.

https://bugs.chromium.org/p/chromium/issues/detail?id=587956

Coincidentally, some 6 months later, Rob M and I paired the same bug with a SOP bypass at #Pwn2Own 2016 to exfiltrate Google Drive files and remotely install an APK via Google Play's web front-end.

https://downloads.immunityinc.com/infiltrate-archives/[Infiltrate]%20Geshev%20and%20Miller%20-%20Logic%20Bug%20Hunting%20in%20Chrome%20on%20Android.pdf

587956 - chromium - An open-source project to help move the web forward. - Monorail