Critical Thinking - Bug Bounty Podcast cover image

Episode 28: Surfin' with CSRFs

Critical Thinking - Bug Bounty Podcast

00:00

Carff: A Cross-App Request for a Tree

Carff is a common exploitation scenario with within mobile apps. It totally breaks CVSS because it's like local only because you need another app on the system. You can go anywhere from the super basic stuff to full RCE. If I recall correctly, that is no longer supported in Chrome and Chromium.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app