writeups.xyz writeups.xyz / Dzmitry Lukyanenka (@Vulnano)

Title Vulnerabilities Programs Authors
Meta Quest: Attacker could make any Oculus user to follow (subscribe) him without any approval
React debug.keystore key was trusted by Meta(Facebook) which caused to Instagram account takeover by malicious apps.
Facebook Messenger for MacOS contained valid hardcoded FB access token (employee's token?)
Global grant uri in Android 8.0-9.0 (2018 year)
Facebook Messenger server random memory exposure through corrupted GIF image