Loading HuntDB...

[PayPal Android] Remote theft of user session using push_notification_webview deeplink

Medium
P
PayPal
Submitted None

Team Summary

Official summary from PayPal

A deeplink feature built into the PayPal Android application failed to validate the requested endpoint. A specifically crafted request from a website or separate app on the device could call the deeplink and direct traffic to any destination. While the impact was limited by compensating controls, headers containing sensitive data could be collected by a malicious actor.

Reported by bagipro

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Open Redirect