Posts

Snapchat Public Profile Information Auto-Saves Without Confirmation

Image
Affected Feature Public Profile editing section, specifically the email and location fields. This is where users manage what personal information appears on their publicly visible Snapchat profile. How to Reproduce Open Snapchat and go to your Public Profile Tap to edit your email or location Start typing something new Don't press the tick (✓) button Just back out or close the keyboard The app saves whatever you typed anyway, even though you never confirmed it.

Understanding Android’s One-Time Permissions and Their Privacy Implications

Image
You know that moment when you carefully set an app's permissions to "Ask every time"? When you go into Settings, find that app, and make sure it only gets access to your microphone or camera when you explicitly allow it? You feel good about it. You're in control, right? Yeah, about that. I've been testing Android's one-time permission system, particularly with apps like WhatsApp. I set the microphone permission to "Ask every time" because I wanted tight control over when the app could listen. But what I discovered was something that doesn't quite match what Android's documentation promises. Guess what? There's a gap. A small one, but it matters. Wait, How Does This Work? Here's the thing most people don't know: when you close an app after granting one-time permission, Android doesn't always revoke it instantly. Think about it. You finish a WhatsApp call, swipe the app away from your recent apps, and assume that's it...

Your Android Phone's Dirty Little Secret - Gemini

Image
You know that moment when you're careful about app permissions? When you go into Settings, find that sketchy app, and revoke its access to your camera, location, or files? You feel good about it. You're in control, right? Yeah, about that. I've been using Google Gemini since it launched. I gave it access to pretty much everything - camera, files, location, the works. Recently, I decided to clean things up. Went into Android settings, revoked all of Gemini's permissions, deleted the app, and reinstalled it fresh. Guess what? Gemini still had access to everything. Wait, How Is That Even Possible? Here's the thing most people don't know: Gemini doesn't actually need your permission if you've already given it to the Google app. Think about it. The Google app comes pre-installed on almost every Android phone. During setup, you probably granted it a bunch of permissions without thinking twice. Camera, microphone, location, files - whatever it asked for,...

When Disconnecting Isn’t Enough: Instagram Messages Leak via Creator Studio

Image
Affected Feature Facebook Creator Studio's Instagram account linking system. Creator Studio lets you manage Instagram messages and comments from desktop by connecting your Instagram account to a Facebook Page. How to Reproduce Connect an Instagram account to a Facebook Page through Creator Studio Use Creator Studio to manage that Instagram account's DMs and comments Go to Facebook settings and disconnect the Instagram account from the Page Go back to Creator Studio You still have full access to read and reply to Instagram DMs and comments The disconnection only removed the visible link. The backend authorization stayed active, so I could keep accessing everything like nothing changed.

Privacy Settings Bypassed: Hidden Likes Still Visible Through Facebook Reels

Image
Affected Feature Facebook's like visibility privacy setting. Users can choose "Only Me" to hide the number of likes on their posts from everyone else. This setting is supposed to keep engagement numbers private. How to Reproduce Create a post on Facebook and set like visibility to "Only Me" Verify the like count is hidden when viewing the post normally Log into a different Facebook account Find the same content in the Reels section The like count is now fully visible, even though it's set to private The privacy setting only applies to the regular post view. When the same content shows up as a Reel, Facebook ignores the setting completely.

TikTok’s Tagging and Mention Settings Bypass: A Simple Business Logic Flaw

Image
Affected Feature TikTok's privacy settings for disabling tags and mentions. Users can turn this off to prevent others from tagging or mentioning them in videos and comments. How to Reproduce Go to TikTok privacy settings and disable tags and mentions Switch to a different TikTok account Try to tag or mention the user who disabled the setting The tag/mention goes through successfully The setting exists in the UI and appears to work, but the backend completely ignores it. Every attempt to tag or mention someone with this disabled still works. Company Response TikTok acknowledged the issue after I reported it and pushed a fix. The setting now properly blocks tags and mentions when disabled.

How I Discovered a ChatGPT Rate Limit Workaround.

Image
Affected Feature ChatGPT's message cap enforcement for GPT-4o users. OpenAI limits how many messages you can send with GPT-4o in a session to manage costs and resources. How to Reproduce Use GPT-4o until you hit the message limit Instead of starting a new chat, click "Share Chat" and copy the link Paste the link back into ChatGPT and send it Click the link and select "Continue this conversation" Send another message - it goes through even though you hit the cap Repeat to keep sending messages beyond the limit The model switches to GPT-3.5 for the extra messages, but you keep the full conversation context and bypass the intended limit. Company Response Reported to OpenAI via Bugcrowd. They confirmed the issue but marked it as a duplicate since another researcher had already reported it. No bounty, but they acknowledged the finding.