homeblogcontact

blog

rssjson
how to gain code execution on millions of people and hundreds of popular apps

2025-02-28

and of course, firebase was (partially) the cause

gaining access to anyones browser without them even visiting a website

2024-09-07

and of course, firebase was the cause (CVE-2024-45489)

how to pwn a billion dollar vc firm using inspect element

2024-07-20

...in about 5 clicks

how we owned almost all of america's fast food chains

2024-01-10

in a really dumb and simple 2 steps

why client-side environment variables are a bad idea

2023-12-23

or, the fuck-ups of a major minecraft/microsoft partner

© 2024 xyzeva