Bypass pin(4 digit passcode on your android app)
Unknown
Vulnerability Details
i have found that this activities are exported
** Package: sh.whisper **
sh.whisper.WMainActivity
sh.whisper.WWhisperBrowserActivity
sh.whisper.WRelatedActivity
sh.whisper.WDiscoverActivity
sh.whisper.WCategoryFeedActivity
sh.whisper.WSettingsActivity
Parent Activity: sh.whisper.WMainV4Activity
sh.whisper.WShareActivity
sh.whisper.WQuickCreateActivity
Parent Activity: sh.whisper.WMainV4Activity
sh.whisper.WUserActivity
sh.whisper.WNotificationsActivity
sh.whisper.WInboxActivity
sh.whisper.WParseDeepLinkActivity
sh.whisper.WAddGroupActivity
whisper android app have a 4 digits PIN that can be set by the user to protect from unauthorized access if the phone is lost(protection for user's inbox and notification) , but **sh.whisper.WNotificationsActivity**
and **sh.whisper.WInboxActivity** are exported ,so any android app can called these activities to bypass the **4-digit code**
watch this video on have i bypass the 4-digit code
** references**
http://cwe.mitre.org/data/definitions/926.html
Actions
View on HackerOneReport Stats
- Report ID: 50884
- State: Closed
- Substate: resolved
- Upvotes: 3