@xssdoctor I hope you find something. I was actually able to run it locally in my own environment using NanoHTTPD on Android. It’s not limited to localhost either; it also works with local IP addresses.
@xssdoctor After a few organizations marked the same issue as out of scope, I stopped pursuing it, but I still think there are things worth investigating here.
@xssdoctor I’ve submitted reports to many organizations, but most of them marked my reports as Informative because the attack required the victim to install a malicious application.
@xssdoctor Was the report considered valid? I found a very similar vulnerability in a Google OAuth application, but they marked my report as out of scope because the victim had to install a malicious application on their device.