Lab - NexMart

Mobile Hacking Conference CTF

NexMart is a hot new retail app built with React Native. Their engineering team is proud of their "modern" stack — all deep-link routing logic and business logic live in a Hermes bytecode bundle that ships with the app.

No one can read that, right? check.

Objective
  • Chain multiple vulnerabilities to achieve Remote Code Execution within the app's process and read the flag from internal storage:

Course Lessons