Identified 25+ vulnerabilities across web and Android surfaces, ranging from critical to informational severity. Covered injection flaws, broken authentication, insecure direct object references, and sensitive data exposure.
Documented each finding with reproduction steps and severity ratings so the engineering team could triage and fix efficiently.
Assessed web and Android apps, working directly with engineers to verify fixes and review implementation.