
Account Takeover through XSS on websites is nothing new. But does the same attack vector exist on Android?
This was one of the most complex findings we came across in 2025.
flawseekr.com/xss-in-android…

English
Novran.
162 posts

@xchopath
Not your favourite infosec guy. Full-time Father.



HTML Injection That Paid $3K Main issue: most websites only rely on SameSite cookies for CSRF protection. No XSS? No problem. HTML Injection + <form> can still trigger sensitive actions. Hope this helps! Honorable mention to my bug bounty partner @fariqfgi 🙌






Bug Bounty Tip: Don't compare your day-to-day with someone else's wins. Behind every $10K bug post are dozens of duplicates, N/As, and dead ends. Stay consistent; that's what really counts.

