Web Hack List

Collected research

Unleashing the Walking Dead: Understanding Cross-App Remote Infections on Mobile WebViews

Cross-app URL invocation lets a remote web page navigate another Android app's WebView, so malicious web content spreads between apps and persists there. The authors name this XAWI and chain infected apps' separate privileges into remote phishing, faking a login UI inside the real app's own WebView, and privilege escalation; fuzzing found about 7.4 percent of top apps exposed.

Record

Researcher
Tongxin Li, Xueqiang Wang, Mingming Zha, Kai Chen, XiaoFeng Wang, Luyi Xing, Xiaolong Bai, Nan Zhang and Xinhui Han
Published by
acmccs.github.io
Format
Whitepaper
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Tongxin Li, Xueqiang Wang, Mingming Zha, Kai Chen, XiaoFeng Wang, Luyi Xing, Xiaolong Bai, Nan Zhang and Xinhui Han, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .