KuCoin Disclosed Report

Bug bounty report KuCoin

Critical Security Flaw: Open Redirect Vulnerability in "KuCoin Crypto Market App"

Company
Created date
Jan 29 2024

Target

KuCoin Mobile Application for Android

Vulnerability Details

Hy team

I identified an open redirect vulnerability in the Android crypto market app while inspecting the app's DEX files. During my investigation, I initially focused on potential issues within the app's WebView. Eventually, I discovered a deep link that, when clicked by the victim, triggered a redirection sequence. The app redirected the victim to a malicious website, following a scenario reminiscent of a new stacking and earning process. This vulnerability poses a potential security threat, warranting attention and remediation

##Vul_deepLink:

kucoin:///external/link?url=https://attacker.io

impact:

The identified open redirect vulnerability in the Android crypto market app can have a significant impact on user security. Exploiting this flaw could lead to unauthorized redirections, potentially exposing users to malicious websites. This creates a heightened risk of phishing attacks, data theft, or other harmful activities. The impact extends beyond the app itself, affecting the trustworthiness of the entire platform and putting users' sensitive information at risk. Immediate attention and remediation are crucial to mitigate these potential consequences.

Validation steps

##Step to reproduce:

  1. make file html and use the following code:
<h1>this is GET form</h1><a href="kucoin:///external/link?url=https://attacker.io">Open Deep Link</a>
  1. run the file on the browser and click to the link
  2. now it will run the malicios website

Attachments

VID-20240129-WA0001.mp4
IMG-20240129-WA0000.jpg
CommentsReport History
Comments on this report are hidden
Details
Statedisclosed
Severity
None
Bounty
hidden
Visibilitypartially
VulnerabilityOpen Redirect
Participants (3)
author
manager
manager