
Episode 28: Surfin' with CSRFs
Critical Thinking - Bug Bounty Podcast
00:00
Carff: A Cross-App Request for a Tree
Carff is a common exploitation scenario with within mobile apps. It totally breaks CVSS because it's like local only because you need another app on the system. You can go anywhere from the super basic stuff to full RCE. If I recall correctly, that is no longer supported in Chrome and Chromium.
Transcript
Play full episode