4 ms·
The study is available here[0]. The gist is that an app can launder a request it isn't privileged to make through another app that is privileged and doesn't cor
by rainforest 9y ago
The study is available here[0]. The gist is that an app can launder a request it isn't privileged to make through another app that is privileged and doesn't correctly check the intent sender. There are examples in Section 4.3.
[0] : http://people.cs.vt.edu/danfeng/papers/AsiaCCS-17-Yao.pdf http://people.cs.vt.edu/danfeng/papers/AsiaCCS-17-Yao.pdf
- HillaryBriss 9y agomaybe i'm reading it wrong, but a lot of the examples in section 4.3 look like one app inadvertently sending sensitive data to another app (in an intent object). i.e. the receiving app is getting some sensitive data it isn't supposed to have but didn't ask for, and then handling it inappropriately (e.g. leaking it to a log).