Field notes

Writeups

● live clk --:--:-- long form

AndroScope paper plus redacted field cases.

notes // livelab
radar--:--:--
wpsniper page-template LFInextforge class matrixbearer on custom schemegitlab file-readunclaimed ms-msakeycloak reset wpsniper page-template LFInextforge class matrixbearer on custom schemegitlab file-readunclaimed ms-msakeycloak reset

WPSniper — page-template LFI class

wordpress

CVE-2026-87902. get_page_template include. VULN only on unique PEAR banner. Detect-only.

2026 · platform · CVE

NextForge — Next.js class matrix

next.js

One-file lab scanner. Profile App/Pages/middleware. Matching RCE / SSRF class. Curl + report snippet. Host stripped.

2026 · platform · tool

Bearer token on an unverified scheme

oauth

Server 302 to a custom scheme carrying the access token. Chooser hijack. Vendor stripped.

2026 · field case · redacted

Unauthenticated GitLab file-read

platform

CVE-2026-85706. Workhorse miss, Puma route, File.open before auth. Classifier only.

2026 · platform · CVE

Unclaimed ms-msa scheme

mobile

CVE-2026-26123. Authenticator emitted ms-msa:// and did not claim it.

2026 · mobile · CVE

Reset-credentials ATO class

auth

CVE-2026-18963. Keycloak forgot-password. Unscoped selector plus unverified email action.

2026 · platform · CVE

Empty join key, admin token

auth

CVE-2026-82329. Self-hosted Artifactory trusted a blank join key. No mint kit.

2026 · platform · CVE

Provider selection is SQL

sqli

Exported ContentProvider glued selection into the query. Bind args unused.

2026 · field note · lab

DEX from a writable path

rce

Loader mapped a file the extract path could overwrite. No payload DEX.

2026 · field note · lab

Bridge on the wrong origin

rce

addJavascriptInterface on a WebView that later loaded an extra URL.

2026 · field note · lab

Conscrypt owns the CA list

tls

Mainline APEX store wins. User CA is a spectator. Observer only.

2026 · field note · lab

Wallet link, static client id

fintech

Static PIN client id, empty bot gate, unlink reset, emulator posture. Vendor stripped.

2026 · field case · redacted

Intent redirection

mobile

Exported router starts a nested Intent. Safer Intents not armed.

2026 · field case · lab

FileProvider, root-path

mobile

paths.xml mapped /. grantUriPermissions on. No file read here.

2026 · field case · lab

WebView, intent://

mobile

parseUri on a document URL, then startActivity.

2026 · field case · lab

The SDK exported the proxy

mobile

Merged AAR activity. Host UID. Nested Intent sink.

2026 · field case · lab

Deeplink into the auth flow

mobile

Exported gate, no host allowlist, private AuthFlow on the other side.

2026 · field case · lab

Wireless debugging trust class

platform

adbd can trust a LAN peer too soon. Observer only. CVE-2026-0073.

2026 · field note · credited

Hardcoded Entra token in public JS

web

Employee JWT with Admin role left in a dated dashboard bundle.

2026 · field case · redacted

mTLS on the device

mobile

AndroScope defense module. Software PKCS12 vs AndroidKeyStore. No public bypass kit.

2026 · field note

Password in the query string

mobile

RN login put the password in the URL. Error SDK copied it.

2026 · field case · redacted

Custom scheme, no PKCE

mobile

Unverified OAuth redirect plus no code_challenge.

2026 · field case · redacted

AndroScope — the instrument

mobile

Rootless model, static engine, radar scoring, live-session rules.

2026-07 · 16 min