Zero-Click Mobile Security Exploitation

Employer not named by the sourceRemote

Cyber Security

Apply on the company’s site

Frontier is not the employer and does not collect applications.

About this role

Penetration Testing, Reverse Engineering · Submission Type Vulnerability Disclosure / Bug Bounty Submission

Submission Category Mobile Security — Zero-Click Exploitation

Severity Classification Critical (CVSS 9.0–10.0)

1. Submission Summary This submission describes a discovered zero-click attack chain affecting mobile messaging applications on both iOS and Android platforms. The vulnerability allows an attacker to compromise a target device without any user interaction. This document serves as the formal description for researchers, security teams, and bug bounty programs to evaluate, reproduce, and remediate the reported issue.

Submitted by: [Researcher Name / Handle] Contact: [Secure Email / PGP Key] Date of Discovery: [Date] Disclosure Type: Coordinated / Responsible Disclosure

2. Vulnerability Overview What was found: A chain of vulnerabilities enabling zero-click remote code execution on mobile devices through a messaging application.

Where it was found: Mobile messaging client on iOS and Android

How it was found: [Fuzzing / Static analysis / Manual code review / Traffic analysis / Reverse engineering]

Why it matters: An attacker can compromise a target device with no user interaction — no clicks, no downloads