Research Vulnerabilities

A Stripe Checkout Detour Around Linktree’s Android WebView Guard

I found a route bypass in Linktree’s Android app. A crafted deep link could open an arbitrary website inside Linktree, give the page a trusted-looking title, and hide the separate domain label. I reproduced the behavior on version 3.59.0 installed directly from Google Play.

I reported the issue through Bugcrowd. Bugcrowd deemed it out of scope.

The Route That Was Supposed to Be Blocked

Linktree’s /mobile-redirect handler accepts an app_dest parameter that names a screen in the app. It explicitly blocks direct navigation to two screens that display web content: Webview and ShopWebview.

A third screen, StripeCheckoutWebview, was allowed. That screen checks whether its URL belongs to checkout.stripe.com. When the URL fails the check, it sends the same navigation parameters to the generic Webview screen. The result is a route the external handler would have blocked if it had been requested directly.

External deep link
  → StripeCheckoutWebview, which the handler permits
  → Non-Stripe URL triggers a fallback
  → Generic Webview, which the handler blocks directly

The handler also forwards the deep link’s other parameters. Those include the page URL, the modal title, and showDomainName, which controls whether a separate domain label appears.

A Harmless Reproduction

I used https://example.com/ as the destination. The following custom-scheme link captures the relevant parameters:

linktree://mobile-redirect?app_dest=StripeCheckoutWebview&url=https%3A%2F%2Fexample.com%2F&title=Linktree%20Secure%20Login&showDomainName=

The empty showDomainName value matters. In the reproduced result, Linktree displayed Linktree Secure Login as the modal heading, rendered the Example Domain page beneath it, and showed no separate origin label.

I delivered the link through an ordinary browser page to a stock Android emulator. The Linktree app came directly from Google Play. It was not rooted, patched, re-signed, or instrumented for this test. When the app was initially signed out, it deferred the link and opened it after I completed sign-in and onboarding.

Why It Matters

A person who opens the crafted link while signed in sees an external page inside Linktree’s own interface. An attacker who controls that page could present a convincing sign-in or support form and collect information that the person chooses to enter. The attacker can also choose the modal heading and suppress the separate domain label, making the page’s origin harder to identify from the app UI.

The proof establishes the in-app page load and the misleading presentation. It does not establish automatic credential theft, access to native app functions, or theft of Linktree cookies from another web origin. My test page contained no form and collected no data.

The Fix

The external redirect handler should allow only routes intended for external invocation. StripeCheckoutWebview should reject a non-Stripe URL instead of forwarding it to the generic WebView. The final WebView should enforce its own destination rules, and an external link should not be able to hide the page’s origin or supply a trusted-looking title.

The confirmed test applies to Linktree Android 3.59.0 on September 15, 2026. I have not established whether a later release changed this behavior. Bugcrowd’s out-of-scope decision is the disposition of my submission, not a claim that the behavior was fixed or accepted as a vulnerability.

Leave a Reply

Your email address will not be published. Required fields are marked *