Back to directory
WRITEUP #2473

React debug.keystore key was trusted by Meta(Facebook) which caused to Instagram account takeover by malicious apps.

Auth BypassAccount takeoverAndroid
by@vulnano(Dzmitry Lukyanenka)
Bounty
12,000
Program
Meta / Facebook
Published
Jul 19, 2022
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://www.vulnano.com/2022/07/react-debugkeystore-key-was-trusted-by.html
RELATED WRITEUPS
Interesting Story of an Account Takeover Vulnerability
Auth BypassAccount takeover
Instagram and Meta 2FA Bypass by Unprotected Backup Code Retrieval in Accounts Center
Auth Bypass2FA / MFA bypass
Forced SSO Session Fixation
Auth BypassSSO
Account takeover on 8 years old public program
Auth BypassAccount takeover
$500 for Cracking Invitation Code For Unauthorized Access & Account Takeover
Auth BypassAccount takeover

Built with ❤️ by Shubham Rawat