😨 From JSInterface bug to 1-click RCE and a 5-figure bounty...
A while ago, our teammate Lyes found a vulnerability in an Android app that eventually earned a 5 figure bug bounty payout.
Finding and validating the full chain manually took ~4 days, which later sparked a simple question. 👇
How much time would this take using
Djini.ai?
In the blog post, Lyes walks through both perspectives.
First, the exploit chain as it was pieced together manually.
Then, how the same risky surface surfaced again when retraced with Djini, but in significantly less time.
👉 Full write-up:
lnkd.in/eNHkFMM8