This page tracks my vulnerability disclosures. Inspired by the P0 folks, this follows a 90-day deadline policy. Disclosure Policy 90-day deadline from the date a vulnerability is reported After the deadline expires, details may be publicly disclosed regardless of fix status If a fix is released, disclosure may occur sooner Extensions may be granted (e.g., coordinated disclosure) Active Reports…
On Android 16, a regular app with no special permissions can leak the user’s real IP, even with “Always-On VPN” + “Block connections without VPN” turned on. Those two settings are supposed to be the hard guarantee that nothing leaves the device outside the tunnel. They don’t hold here. The trick is that the app doesn’t send the packet itself. It hands the…
A collection of low severity and “won’t fix” vulnerabilities from my recent security research. These didn’t meet the bar for a formal advisory but are documented here for transparency. Table of Contents ADB Fastdeploy Command Injection ADB Public Key Newline Injection Recovery System Argument Injection ADB Fastdeploy Command Injection When adb install is called with…
Security engineer based in Zurich. Interested in low-level stuff, the kind where you stare at disassembly for hours. I spend most of my time breaking Android userspace these days. @cybaqkebm • yexploit@proton.me