This is a writeup detailing a Denial of Service (DoS) vulnerability in Grindr v2.1.1 iOS mobile web-application. The vulnerability is triggered by injecting script code or termination strings into the Display Name field, causing the app to crash when a user attempts to copy a social network link.
Classification
Writeup 90%
Target:
Grindr iOS Mobile Web Application (API) 2.2.1
Auth required
Prerequisites:
Access to the Grindr mobile application · Ability to edit the Display Name field