In reply to @v12sec

V12

V12

@v12sec · Twitter ·

What happens after the tap: - A crafted link opens Ditto. - The app checks the host, but not the scheme. - The decoded path is concatenated into JavaScript. - The attacker escapes the string. - Their code runs inside Ditto’s privileged WebView.