[PayPal Android] Remote theft of user session using push_notification_webview deeplink
Medium
P
PayPal
Submitted None
Team Summary
Official summary from PayPal
A deeplink feature built into the PayPal Android application failed to validate the requested endpoint. A specifically crafted request from a website or separate app on the device could call the deeplink and direct traffic to any destination. While the impact was limited by compensating controls, headers containing sensitive data could be collected by a malicious actor.
Actions:
Reported by
bagipro
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Open Redirect