MobileHackingLab — Runtime Toad Writeup
Exploiting CVE-2025-59489 in Unity's runtime — local and remote RCE via -xrsdk-pre-init-library intent extras.
Filter every CVE deep-dive and write-up by title, CVE id, vendor, tag, or body text. Matches are found across all pages, not just this one.
16 posts
Exploiting CVE-2025-59489 in Unity's runtime — local and remote RCE via -xrsdk-pre-init-library intent extras.
Unvalidated implicit intent data lets a malicious app return an internal file:// URI, which AnkiDroid copies into a world-readable cache directory.
Chaining path traversal in getLastPathSegment() with unverified native library loading for RCE on MobileHackingLab's Document Viewer.
Speedrun of the mobile track at Nahamcon CTF 2024: logcat, strings, Godot script extraction, Flutter instrumentation, and Frida hooking.
OS command injection via an unsanitized path string extra in DatabaseViewerActivity.java allows arbitrary command execution when root explorer mode is enabled.
Mobile challenge solutions from TCP1P CTF: exported activity exploitation, implicit intent hijacking, and a WebView/JS interface/content provider chain.
Theft of arbitrary files via lack of intent validation and insecure provider paths in TTFViewerActivity.kt.
Theft of arbitrary files via execution of attacker-controlled bash scripts through the exported BashAssociation activity.
Improper validation of intent data in TextViewerActivity allows a malicious app to open arbitrary files from Inure's private storage.
Theft of arbitrary files from a non-exported FileProvider via improper setResult() in a third-party welcome screen library.
Nothing matches that.