3 ms·
Is anyone familiar with the code that allows this vulnerability to be present and where I can find it(I believe this project is open source)? I understand the e
by slingerofwheat 12y ago
Is anyone familiar with the code that allows this vulnerability to be present and where I can find it(I believe this project is open source)? I understand the exploit is adding a nullbyte at the beginning of some javascript due to some bad handling in the parsing code. So I'm looking here: https://android.googlesource.com/platform/packages/apps/Browser/+/master/src/com/android/browser https://android.googlesource.com/platform/packages/apps/Brow...
- joev_ 12y agoI don't know the exact location, but it is probably somewhere in the webview tree, since it affects apps that embed webviews as well: https://android.googlesource.com/platform/frameworks/base/+/jb-release/core/java/android/webkit/ https://android.googlesource.com/platform/frameworks/base/+/...
- smtddr 12y agoSince it's both webview and browser itself, I'd suspect some kind of common denominator object at fault... like...https://android.googlesource.com/platform/frameworks/base/+/jb-release/core/java/android/net/UrlQuerySanitizer.java https://android.googlesource.com/platform/frameworks/base/+/... Especially with a method called "public static class IllegalCharacterValueSanitizer".