Skip to content
A big list of Android Hackerone disclosed reports and other resources.
Branch: master
Clone or download
Latest commit 24e6504 Jul 27, 2019
Type Name Latest commit message Commit time
Failed to load latest commit information. New reports! Jul 27, 2019


HackerOne Reports

Hardcoded credentials

Disclosure of all uploads via hardcoded api secret

Insecure deeplinks

Sensitive information disclosure


RCE in TinyCards for Android - TinyCards made this report private.

SQL Injection

SQL Injection in Content Provider

Session theft

Steal user session

Steal files

Token leakage due to stolen files via unprotected Activity

Steal files due to exported services

Steal files due to unprotected exported Activity

Steal files due to insecure data storage

Insecure local data storage, makes it easy to steal files


Golden techniques to bypass host validations

Two-factor authentication bypass due to vuln endpoint

Another endpoint Auth bypass

Bypass PIN/Fingerprint lock

Bypass lock protection


HTML Injection in BatterySaveArticleRenderer WebView

XSS via SAMLAuthActivity

XSS in ImageViewerActivity

XSS via start ContentActivity

XSS on Owncloud webview

Privilege Escalation

Intent Spoofing

Access of some not exported content providers

Access protected components via intent

Fragment injection

Javascript injection

Intercept Broadcasts

Possible to intercept broadcasts about file uploads

Vulnerable exported broadcast reciever

View every network request response's information

Practice Apps


Vulnerable Android application for developers and security enthusiasts to learn about Android insecurities

Damn Insecure and Vulnerable app

Damn Insecure and vulnerable App for Android


OWASP GoatDroid is a fully functional and self-contained training environment for educating developers and testers on Android security

Sieve mwrlabs

Sieve is a small Password Manager app created to showcase some of the common vulnerabilities found in Android applications.


OWASP top 10 2016

OWASP mobile testing guide

Android Reversing 101

Detect secret leaks in Android apps online

Android Security Guidelines

Attacking vulnerable Broadcast Recievers

Android Webview Vulnerabilities

Android reverse engineering recon

Webview addjavascriptinterface RCE

Install PLayStore On Android Emulator

Android Bug Bounty Tips

You can’t perform that action at this time.