Critical Thinking - Bug Bounty Podcast · Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

Episode 161: Cross-Consumer Attacks & DTMF Tone Exfil

·25 min·1 clip
A tapjacked intent URI inside Gemini let the attacker preload a prompt, read messages, and call the exfiltration number.
1. Critical Thinking - Bug Bounty Podcast Episode 161 focuses on Gemini exfiltration, CSRF behavior, the YesWeHack 2026 report, and cross-consumer attacks. 2. The host, who speaks as a bug bounty hunter and researcher, links personal findings to reports from YesWeHack, HackerOne, and a Tokyo live hacking event. 3. The episode asks what happens when modern bug bounty tactics meet AI actions, iframe limits, and third-party hosted content. 4. The YesWeHack 2026 report is based on 245 surveyed hackers and says most use AI for report clarity and structure. 5. The same report says 32% use AI to think creatively, 31% to find more subtle bugs, and 40% for payload generation. 6. The host says he has had success using Opus 4.6 on client-side bugs and recommends JackScout, Cloud Code, and JavaScript analysis for routes, query parsing, hash parsing, and postMessage listeners. 7. Another report detail says 44% of hunters have been hacking for three to five years, while 38% are full-time hunters on YesWeHack. 8. The host highlights a 520% increase in collaboration reports on YesWeHack and notes Burp Suite, FUF, and HPX as the top tools. 9. On page 55, the report ranks hunters by CWE type, with Go Diego shown as top for cache poisoning and doxing associated with subdomain takeovers. 10. The host also points to methodology sections for stored XSS, information disclosure, and a research piece titled "Exploiting syntax confusions in the wild" by Alex Berman. 11. The CSRF segment comes from a recent exploit where X-Frame-Options: deny did not stop the state-changing request from being processed server side. 12. The host says same-site cookies were still sent in the iframe, so the blocked response did not matter once the request had already executed. 13. He describes creating multiple iframes to repeat the action and says the important check for CSRF is whether same-site cookies are in place. 14. The Gemini write-up comes from a collaboration with Monke, Rezo, the host, and Lupin at a live hacking event in Tokyo. 15. The delivery method used an intent URI inside the Gemini app and tapjacking so a victim could preload a prompt with repeated taps. 16. The host says the data source was the user's messages on Android, then the exfiltration path encoded a 2FA code into DTMF tones and appended it to a phone number. 17. The proof-of-concept involved a second phone hearing the tones and showing the code, and the team received a bounty and a 1 through 3,7 bonus for creativity. 18. The episode mixes rapid-fire news, opinionated commentary, and technical walkthroughs with a casual "sup hackers" delivery. 19. Listeners who enjoy bug bounty tactics, AI abuse, and platform reports will get the most value. 20. Listeners wanting polished long-form interviews or nontechnical stories may skip it.
Listen to the show on