Sergey Toshin
146 posts

Sergey Toshin
@_bagipro
Ranked as the #1 security researcher for Google Play Security Rewards Program. The founder of @OversecuredInc Android and iOS vulnerability scanners
Katılım Aralık 2015
186 Takip Edilen7K Takipçiler

Interested? Fill out the form: docs.google.com/forms/d/e/1FAI…
English

New Android host validation bypass technique!
[1/4] All parsed URIs in Android are android.net.Uri.StringUri objects. However, the scheme parser only looks for the ":" delimiter



English

Wait, Temu (the infamous online sale app) was abusing CVE-2023-20963 on Android devices until they caught the developer and removed it? I want full analysis for that case alone!
Oversecured@OversecuredInc
🚨 Security Alert: Over 2 billion Android users and 100 million Pixel users may be at risk of file theft, VPN bypass, unauthorized Bluetooth access, and geolocation leaks. Visit our blog for details. blog.oversecured.com/Disclosure-of-…
English

@hkashfi 2/2 However, based on exploit codes and other public comments, it's not about "spying on its users", but about advertising itself in rural Chinese areas
English

@hkashfi 1/2 This story isn't about the abuse of CVE-2023-20963. I've personally checked the exploit pack used by the PDD app, it contained about 50 exploits, most of them for different Android vendors (LG, Xiaomi, Huawei, Samsung, etc)
English
Sergey Toshin retweetledi

🚨 Security Alert: Over 2 billion Android users and 100 million Pixel users may be at risk of file theft, VPN bypass, unauthorized Bluetooth access, and geolocation leaks. Visit our blog for details.
blog.oversecured.com/Disclosure-of-…
English

@MishaalRahman @EpicGames It seems to be INSTALL_PACKAGES if you want to install an app without any user interaction. But on the latest Androids, it's a hell from the user's perspective to get such a permission granted for a non-default/pre-installed app, similar to getting device admin permissions
English

@_bagipro @EpicGames You're saying they want to avoid having to request the REQUEST_INSTALL_PACKAGES permission? I guess that makes sense given their arguments in court.
English

Curious why the @EpicGames app for Android doesn't use Android's session-based installation API. Instead, it tries to install APKs by sending the android.intent.action.VIEW intent and letting the system Package Installer app handle the installation.
Unless I'm mistaken, since it's using the non-session based installation method, then Epic Games Store can't take advantage of the Android APIs that would let it update apps without user action (introduced in Android 12) or declare update ownership (introduced in Android 14).
Any ideas @TimSweeneyEpic?

English

We have updated scan reports for all Google phone apps and additionally included reports for Wear OS, Android TV, Android Desktop, and Android Auto!
Time to report the vulnerabilities to bughunters.google.com!
blog.oversecured.com/Oversecured-Ap…
Sergey Toshin@_bagipro
Android bug hunters, your chance to get rewards from Google Only Google has agreed to release the reports without prior fixes. I see dozens of valid bugs (and I submitted 0 of them)
English
Sergey Toshin retweetledi

NEW - A whole bunch of fresh Xiaomi vulnerabilities discovered by researchers who say they're serious and all users should update ASAP.
forbes.com/sites/thomasbr…
English
Sergey Toshin retweetledi

🔎📱 We found 20 vulnerabilities in Xiaomi apps that could have let someone steal your data. No worries, it's already fixed. To keep your data safe, update your phone.
blog.oversecured.com/20-Security-Is…

English


