Collected research
Android web attack surface
Maps Android browser-to-app intent routes that lose browser origin, activation or launch restrictions. Firebase, market and augmented-reality handlers provide concrete relay and WebView examples. The account distinguishes intended native facilities exposed through unsafe routing from browser bugs, and states prerequisites for privileged bridge access.
Record
- Researcher
- NDevTK
- Published by
- NDevTK
- Date
- Topic
- Other
In the archive
Related sources
- Home-screen spoof demonstration
- Clock and alarm demonstration
- Intent spoof demonstration
- Browser spoof demonstration
- Non-BROWSABLE relay demonstration
Tags
This page is the archive's own catalogue record. The research is the work of NDevTK, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .