Web Hack List

Collected research

Unauthorized Origin Crossing on Mobile Platforms: Threats and Mitigation

Mobile OSes lack the browser's origin checks on cross-app channels, so intents, URL schemes and web-accessing utility classes let one app cross into another's web origin. Surveying those channels on Android and iOS, and how the Facebook and Dropbox apps use them, yielded credential theft and text-input capture. Morbs labels each message with its origin and enforces policies.

Record

Researcher
Rui Wang, Luyi Xing, XiaoFeng Wang and Shuo Chen
Published by
Microsoft Research
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Rui Wang, Luyi Xing, XiaoFeng Wang and Shuo Chen, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .