Samsung_Vulnerabilities
Oversecured discloses a report of 176 vulnerabilities discovered in Samsung preinstalled apps between 2022 and 2025, with 140 detailed, all fixed in collaboration with Samsung.
Incorporates a three-state comparison model with body normalisation, canary markers, and WAF/rate-limit guards to minimise false positives, and provides native GraphQL and multi-tenant support.
A Burp Suite extension for cross-identity / cross-tenant access-control testing — BAC, IDOR, BOLA, and privilege escalation.
Authz-ExeC replays every request you make as a privileged user using each identity you configure (a low-privilege user, a second tenant, unauthenticated), compares each response against the privileged one, and shows a live colour matrix of where access control held, broke, or needs review. Think Autorize / AuthMatrix — rebuilt on the modern Montoya API, hardened against false positives, with first-class multi-tenant and GraphQL support.
⚡ Core
Cookie, Authorization (JWT), and arbitrary headers (X-Tenant-Id,
X-Api-Key, …), strip all auth (unauthenticated), or apply regex ID-rewrite rules for BOLA.alg:none / strip-signature helpers).🎯 Accuracy (low false-positive)
200 + "access denied"), empty
results (row-level filtering), and login redirects. Per-verdict confidence score.🧩 Coverage
204/header-based
responses; skips only rendered HTML pages.Burp Suite extension for cross-identity & cross-tenant access-control testing — BAC, IDOR, BOLA, and privilege escalation.
Similar projects matched by category, topics, and programming language.
Oversecured discloses a report of 176 vulnerabilities discovered in Samsung preinstalled apps between 2022 and 2025, with 140 detailed, all fixed in collaboration with Samsung.

An LSPosed module that hooks MIUI SystemUI back gestures using modern Xposed API 102 for research and customization.
OneStep4.0 is a multi-window desktop container for Android that requires root or system-level privileges, enabling a main window with several side windows for efficient app multitasking.