Awesome Open Source
Awesome Open Source


HackerOne Reports

Hardcoded credentials

Disclosure of all uploads via hardcoded api secret


Android security checklist: WebView

Insecure deeplinks

Account Takeover Via DeepLink

Sensitive information disclosure


Why dynamic code loading could be dangerous for your apps: a Google example

RCE in TinyCards for Android - TinyCards made this report private.

Persistent arbitrary code execution in Android's Google Play Core Library: details, explanation and the PoC

CVE-2020-8913: Persistent arbitrary code execution in Google Play Core library - Persistent arbitrary code execution in Android's Google Play Core Library: details, explanation and the PoC - CVE-2020-8913

TikTok: three persistent arbitrary code executions and one theft of arbitrary files - Oversecured detects dangerous vulnerabilities in the TikTok Android app

Memory corruption

Exploiting memory corruption vulnerabilities on Android - Exploiting memory corruption vulnerabilities on Android + an example of such vulnerability in PayPal apps


Use cryptography in mobile apps the right way

SQL Injection

SQL Injection in Content Provider

Session theft

Steal user session

Steal files

Android security checklist: theft of arbitrary files

How to exploit insecure WebResourceResponse configurations + an example of the vulnerability in Amazon apps - Android: Exploring vulnerabilities in WebResourceResponse

Vulnerable to local file steal, Javascript injection, Open redirect

Token leakage due to stolen files via unprotected Activity

Steal files due to exported services

Steal files due to unprotected exported Activity

Steal files due to insecure data storage

Insecure local data storage, makes it easy to steal files


Golden techniques to bypass host validations

Two-factor authentication bypass due to vuln endpoint

Another endpoint Auth bypass

Bypass PIN/Fingerprint lock

Bypass lock protection

Bypass of biometrics security functionality


HTML Injection in BatterySaveArticleRenderer WebView

XSS via SAMLAuthActivity

XSS in ImageViewerActivity

XSS via start ContentActivity

XSS on Owncloud webview

Privilege Escalation

Common mistakes when using permissions in Android

Two weeks of securing Samsung devices: Part 2

Two weeks of securing Samsung devices: Part 1

Intent Spoofing

Access of some not exported content providers

Access protected components via intent

Fragment injection

Javascript injection


Deeplink leads to CSRF in follow action

Case sensitive account collisions

overwrite account associated with email via android application

Intercept Broadcasts

Possible to intercept broadcasts about file uploads

Vulnerable exported broadcast reciever

View every network request response's information

Practice Apps

Oversecured Vulnerable Android App

A vulnerable app showing modern security bugs in Android apps

Damn Vulnerable Bank

Vulnerable Banking Application for Android


Intentionally Vulnerable Android Application


Vulnerable Android Application made with security issues


A vulnerable Android application with ctf examples based on bug bounty findings, exploitation concepts, and pure creativity.


Vulnerable Android application for developers and security enthusiasts to learn about Android insecurities

Damn Insecure and Vulnerable app

Damn Insecure and vulnerable App for Android


OWASP GoatDroid is a fully functional and self-contained training environment for educating developers and testers on Android security

Sieve mwrlabs

Sieve is a small Password Manager app created to showcase some of the common vulnerabilities found in Android applications.


OWASP top 10 2016

OWASP mobile testing guide

Android Reversing 101

Detect secret leaks in Android apps online

Android Security Guidelines

Attacking vulnerable Broadcast Recievers

Android Webview Vulnerabilities

Android reverse engineering recon

Webview addjavascriptinterface RCE

Install PLayStore On Android Emulator

Android Bug Bounty Tips

Android: Access to app protected components

Android: arbitrary code execution via third-party package contexts

Interception of Android implicit intents

Evernote: Universal-XSS, theft of all cookies from all sites, and more

Android: Gaining access to arbitrary* Content Providers

Related Awesome Lists
Top Programming Languages
Top Projects

Get A Weekly Email With Trending Projects For These Topics
No Spam. Unsubscribe easily at any time.
Webview (2,761
Bypass (2,009
Xss (1,733
Information Security (1,250
Owasp (1,057
Hackerone (160
Android Security (111
Android Resources (15