$ whoami
emailof911
security researcher
//
foucused on Android & iOS
write-ups
How a popular Android image cropping library silently exposed thousands of apps to Arbitrary File Overwrite (AFO).
How a cropper library shipped an exported activity + root-scoped FileProvider to half the Play Store, and what we can actually do with the resulting file I/O primitive.
RCE in mexc Android app via Bypass URL validation to access the WebView, JS-Bridge with Path Traversal leads to Native-Library Cache Overwrite.
I chained a JavaScript bridge path traversal with an unvalidated native library cache in the MEXC Exchange Android app to achieve remote code execution