Collected research
Unauthorized Origin Crossing on Mobile Platforms: Threats and Mitigation
Mobile OSes lack the browser's origin checks on cross-app channels, so intents, URL schemes and web-accessing utility classes let one app cross into another's web origin. Surveying those channels on Android and iOS, and how the Facebook and Dropbox apps use them, yielded credential theft and text-input capture. Morbs labels each message with its origin and enforces policies.
Record
- Researcher
- Rui Wang, Luyi Xing, XiaoFeng Wang and Shuo Chen
- Published by
- Microsoft Research
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Rui Wang, Luyi Xing, XiaoFeng Wang and Shuo Chen, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .