High · Published
Cross-Session Session Leakage Through Cached Next.js Responses
How a shared CloudFront cache exposed an HttpOnly session credential embedded in server-rendered Next.js responses.
INDEPENDENT SECURITY RESEARCH
Android, mobile applications, WebViews, deep links, native bridges, web applications, APIs, reverse engineering, and reproducible PoCs.
WebViews, deep links, native bridges and client-side attack surfaces.
Endpoints, authentication, authorization and application trust boundaries.
Practical research with clean, reproducible proof-of-concepts.
FIELD NOTES
RESEARCH
$ whoami
womp — independent security researcher
$ focus --current
android · webviews · api · reverse-engineering · web
$ methodology
"practical research + reproducible PoCs"