We break systems
before attackers do.
Vulnerability research, exploit development, and responsible disclosure across mobile, IoT, web, network and cloud.
Mobile · IoT · Web · Network · Cloud · Since 2025
$ ./lab --status[OK] advisories 1[OK] research 3[OK] publications 0[OK] disclosure coordinatedThe lab in numbers
Latest advisories
Findings we reported, and what the vendor did about them.
From the lab
Deep dives into what we found, and notes from the work around it.
A 1-Click OAuth Token Theft Chain in Bing
Bing for Android shipped four small, individually unremarkable weaknesses. Chained together, a single tap on a link from any web page or another app could steal the victim's Microsoft OAuth refresh token, access tokens, and account PII and send them to an attacker-controlled server.
Intent Redirection in a Samsung Dialer (Duplicate) SVE-2025–1217
Intent Redirection in Samsung Dialer The Duo Call activity did not properly trust or validate an embedded `Intent`, allowing a third-party app to control the redirected `Intent` and abuse the Dialer’s privileged context.
A 1-Click Exploiting Samsung Smart Touch Call
An exported WebView in Samsung's Smart Touch Call takes its URL and HTTP method straight from the intent. Two checks stand in front of it and neither looks at the URL. Samsung closed it as a duplicate; Interrupt Labs took the same entry point to camera and location at Pwn2Own.
What we do
How the lab works with a client. Each engagement is scoped with the researchers who will do it.
Scope an engagement
Most engagements start with a 30-minute scoping call with the people who will actually do the work. No sales funnel.