Android App Bug Bounty Secrets @LiveOverflow
Android App Bug Bounty Secrets  @LiveOverflow
Uploaded July 2023 | Updated September 2026, 2 weeks ago
Sergey Toshin tells us the story of how he became a top Android bug hunter and how he finds critical vulnerabilities. He also shows us a really cool vulnerability found in the Google Android Snapseed app. I didn't know this crazy attack vector exists!

LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Join the Hextree Discord: discord.gg/xgQpCQCpvy

Start Android Bug Hunting Here! Google App Scan Results: bughunters.google.com/report/targets/290590452

Google Mobile VRP: bughunters.google.com/about/rules/6618732618186752/google-mobile-vulnerability-reward-program-rules
Oversecured Blog: blog.oversecured.com
Verify the output of tools: bughunters.google.com/learn/improving-your-reports/avoiding-mistakes/5981856648134656/verify-the-output-of-the-tools

More Bug Bounty Videos: youtube.com/playlist?list=PLhixgUqwRTjxKYsPTegCyL5adZaq5eILt
More Mobile Security: youtube.com/playlist?list=PLhixgUqwRTjxHFDl0OykeqZ-VvnClfDpT

CHAPTERS
00:00 - Intro
00:57 - Meet Sergey Toshin (Oversecured)
02:51 - How Oversecured Started
04:42 - Verify The Output of Tools!
07:17 - First Look at Vulnerability
09:58 - 1. Explained: Android Intents
11:25 - 2. Explained: Content Providers
12:51 - 3. Explained: App Permissions
13:34 - Exploit Walkthrough
16:17 - Proof of Concept and Report
17:15 - Android VRP Rewards
18:32 - Start Hunting for Bugs in Google Apps!

SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com

WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog

#ReverseEngineering #BugBounty #LiveOverflow

(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
Android App Bug Bounty SecretsCybercrime is Not Hacking!Reading Kernel Source Code - Analysis of an ExploitWriting a Simple Buffer Overflow ExploitResearching MissingNo Glitch in PokemonCannot access memory at address // Debugging PIE Binaries affected by ASLR - bin 0x2EDid an AI Really Hack Hugging Face?Exploiting Java Tomcat With a Crazy JSP Web Shell - Real World CTF 2022Public Penetration Test Reports - Learning ResourceMinecraft Reach HackKernel Root Exploit via a ptrace() and execve() Race ConditionExploit Fails? Debug Your Shellcode - bin 0x2B
LiveOverflow |

Android App Bug Bounty Secrets

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER