Web Hack List

Collected research

Cruel Intentions: Violating Browser Security and Privacy Through Web Intents

Security analysis of Web Intents, the browser framework for delegating actions such as sharing between sites. Four attacks are found against the prototype implementations: cross-session user tracking, denial of service on intent storage, overwriting benign intents with malicious ones, and a login CSRF avenue. Origin-isolated intent storage and registration prompts are proposed.

Record

Researcher
Jenna Kallaher, Amal Krishnan, Paul Makowski, Eric Chen and Collin Jackson
Published by
ieee-security.org
Format
Whitepaper
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Jenna Kallaher, Amal Krishnan, Paul Makowski, Eric Chen and Collin Jackson, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .