Security · Findings

What I have found so far.

Every entry here started the same way: a store listing, my own device, my own account, and a few evenings of taking the app apart. Names appear once the developer has had their 90 days. Until then the case is listed, not described.

87
apps taken apart
44
disclosure write-ups
10
CVE requests
100M+
largest install base
Government10M+ installsAndroid · iOSFixed

Nusuk

Ministry of Hajj and Umrah, Saudi Arabia

The official Hajj and Umrah app, used by pilgrims from every country, shipped credentials for a third-party banking channel inside its release build. Reported through CERT/CC; the next store release no longer contains them, and the ministry has confirmed the credentials were rotated.

22
findings
2
critical
Critical
top severity

Timeline

  1. 29 Aug 2026

    Found during a teardown of build 17.4.9

  2. 01 Sep 2026

    Reported through CERT/CC (VINCE)

  3. 06 Sep 2026

    CVE requested via MITRE

  4. 17.5.0

    Credentials no longer in the store build

  5. Sep 2026

    Rotation confirmed by the ministry

Read the write-up

Register

A selection. Ordered by what it would have meant for the people using the app, not by how clever the bug was.

  • Fixed
  • Reported
  • Withheld
  1. Muslim Pro

    Write-up

    Quran and prayer-times app · Bitsmedia · iOS · Android · 100M+ installs

    Any community member’s name and birth date were reachable through a public user ID, along with the follower graph.

    Severity

    High· Access control

    Status

    Fixed

    Fixed within 3 weeks

  2. Knowunity

    Learning platform for students · Android · 10M+ installs

    A production QA console, reachable by deep link, let any user grant themselves Premium and skip payment.

    Severity

    High· Configuration

    Status

    ReportedCVE

    Sep 2026

  3. TripBFF

    Solo-travel social app · iOS

    Identity-verification selfies and group trip chats were readable without signing in. The first fix was incomplete; the re-test said so.

    Severity

    Critical· Data exposure

    Status

    Reported

    Partially fixed

  4. Caller ID and call-blocking app

    Name withheld · Android · 100M+ installs

    Five findings, two of them critical. Re-tested on the latest store build: still open.

    Severity

    Critical· Permissions

    Status

    Under embargoCVE

    Name withheld until 2 Dec 2026

  5. Period tracker

    Name withheld · Android · 100M+ installs

    A partner backend accepted far too little to hand over a full account, including its backups.

    Severity

    Critical· Account takeover

    Status

    Reported

    Aug 2026

  6. Creator analytics app

    Name withheld · Android

    A live session token shipped inside the app bundle, next to an update channel that accepted unsigned code.

    Severity

    Critical· Secrets

    Status

    Reported

    Aug 2026

  7. AI chat app

    Name withheld · Android · 50M+ installs

    Paid AI responses without a valid token, public file uploads, and a database open to anyone who knew the address.

    Severity

    High· Authentication

    Status

    Reported

    Sep 2026

  8. Mosque prayer-times platform

    Name withheld · Web

    The production database answered reads and writes without any sign-in.

    Severity

    Critical· Database

    Status

    Reported

    Aug 2026

  9. Baby monitor app

    Name withheld · Android · 1M+ installs

    The phone in the child’s room served live audio and video to anyone on the same Wi-Fi.

    Severity

    Critical· Network

    Status

    Reported

    Aug 2026

  10. Baby sleep app

    Name withheld · iOS · Android · 1M+ installs

    A second backend let anyone read, change or delete any family’s chat history.

    Severity

    Critical· Access control

    Status

    Reported

    Aug 2026

  11. Antivirus app

    Name withheld · Android · 1M+ installs

    Scare screens shown regardless of the scan result, and hundreds of tracking requests before consent.

    Severity

    High· Deceptive UI

    Status

    Reported

    Sep 2026

  12. Autonomous ride-hailing app

    Name withheld · Android

    Sign-out did not end the session server-side, and the token stayed on disk in clear text afterwards.

    Severity

    Medium· Local storage

    Status

    Internal only

    Sep 2026

9 of 12 entries withheld. Names are added when the disclosure window closes or a fix ships, whichever comes first.

Before it ends up here

Everything above was found without an invitation. If you would rather have the same look at your app while the findings are still yours, I do paid reviews under the same rules.

About the paid reviews