Unclaimed Google Play Store package
文章描述了一起Google Play Store包名劫持事件,因原链接返回404且包名未被注册,存在被接管风险。公司要求提供概念验证,需实际上传应用至商店,但作者尚未创建开发者账号(需支付25美元费用)。作者寻求有账号的志愿者协助上传占位应用,承诺分享10%的漏洞赏金(通常为50-100美元)。 2025-8-8 16:41:11 Author: www.reddit.com(查看原文) 阅读量:11 收藏

I came across a broken link hijacking case involving a Google Play Store package. The app link returns a 404, and the package name is currently unclaimed.which means it can potentially be taken over. It’s a valid security issue and could be eligible for a bug bounty, though I'm not 100% sure.

The company asked for a working proof of concept, meaning the package has to actually be claimed and uploaded to the Play Store. I haven’t created a developer account myself yet, since I haven’t needed one except for this case and it requires a $25 fee.

If you already have a developer account, would you be willing to contribute by uploading a simple placeholder app using that package name, just to prove the takeover? If the report gets rewarded, I’ll share 10% of the bounty with you. Usually, these types of reports are rewarded with $50 or $100, so I hope you understand I can’t offer more than 10%.

Let me know if you’re open to it.

Thanks!


文章来源: https://www.reddit.com/r/netsec/comments/1ml07c1/unclaimed_google_play_store_package/
如有侵权请联系:admin#unsafe.sh