critical Zero-click ATO

Push Notification Forgery via Exported Activity Leads to Zero-Click Account Takeover

Deterministic encryption + exported activity. Forged push notification steals session tokens without any user interaction.

Mar 4, 2026
AndroidAccess ControlCryptography
critical Two-tap wallet drain

Self-Custody Wallet Deep Link Loads Attacker Page With Full Signing Access, Any User Drainable in Two Taps

A self-custody mobile wallet's browse deep link accepted any URL and loaded it inside the in-app dApp browser, where the signing bridge was injected into all origins, enabling a two-tap drain of any user via a phishing link.

Mar 4, 2026
AndroidDeep LinksWallet
high Official branded phishing

Hardcoded Branch.io Key Enables Official Branded Phishing Links

SDK key from APK created unlimited verified deep links. Chained with unfiltered WebView for in-app credential theft.

Mar 4, 2026
AndroidHardcoded SecretsPhishing
high One-click in-app phishing

Exchange Deep Link Loads Arbitrary URL in Authenticated In-App Browser, One-Click Credential Phishing

A centralized exchange's Android deep link handler loaded any attacker URL inside the real app shell with the native JavaScript bridge attached, enabling one-tap credential phishing with no malicious app install needed.

Mar 4, 2026
AndroidDeep LinksPhishing
critical One-tap ATO

Deep Link + JS Bridge Chain to Full Account Takeover

Three chained flaws in a crypto exchange's Android app gave full account access from a single tap.

Mar 2, 2026
AndroidDeep LinksJS Bridge
critical Permanent impersonation

Unauthenticated Zendesk JWT Enables Full Support System Impersonation

No-auth endpoint generated support tokens for any user. Read conversations, download KYC docs, send messages as victim.

Mar 2, 2026
WebAuthenticationData Exposure
high Signature capture via deep link

Wallet Deep Link Loads Arbitrary URL in Privileged dApp Browser, Address and Signatures Captured

A wallet's deep link handler accepted any URL and loaded it inside the privileged in-app browser, where the signing bridge gave attacker pages full access to wallet address, message signing, and typed data signing.

Feb 27, 2026
AndroidDeep LinksWallet
critical 7-month persistence

1-Click Account Takeover via Deep Link Domain Validation Bypass

Flawed domain check allowed attacker URL in WebView. Session token stolen in under 2 seconds, valid for 7 months.

Feb 26, 2026
AndroidDeep LinksInput Validation
critical All users affected

Hardcoded RSA Key in Native Library Enables Remote Wallet Compromise

RSA-2048 key extracted from a .so file in 5 seconds. Forged push notifications to any wallet user.

Feb 26, 2026
AndroidReverse EngineeringHardcoded Secrets
critical 250K wallets deanonymized

Unauthenticated GraphQL Endpoint Leaks Emails, IP-to-Wallet Mappings, Push Tokens, and Support Messages

A wallet provider's GraphQL endpoint allowed any anonymous caller to read user emails, 250K IP-to-wallet mappings, 80K push tokens, and private support messages, deanonymizing blockchain users at scale.

Feb 26, 2026
WebGraphQLPII Exposure