Introducing Source Code Connect your repository and scan any branch, commit, or tag for actionable source code findings. Try it now

Mohamed Nasser

Articles by Mohamed Nasser

Ostorlab's Pentest Engine identified a JavaScript bridge exposure in an Android WebView, allowing unauthenticated native method invocation via deep links. This case study details how the engine bypassed insecure Intent handling to manipulate the native UI, validating a potent social engineering vector while confirming the effectiveness of the underlying sandbox.