3 ms·
Aside from profiling, can these custom URL handlers also be used as an attack vector on other installed applications? That is, assuming any of those happens to
by elmo2you 5y ago
Aside from profiling, can these custom URL handlers also be used as an attack vector on other installed applications?
That is, assuming any of those happens to be installed and have a (input sanitation related) vulnerability.
Maybe I'm just seeing ghosts here. But the idea of a web site pushing malicious links to whatever software may also be installed on the same machine, isn't a very comforting thought.
- kdarutkin 5y agoThis is possible in theory. For example, Safari opens the Apple Music without any user prompt. The app itself is designed to handle deep links (such as opening an album or starting the song). That means you can perform a deep link forgery, in order to force the app to perform unwilling action without user confirmation.