Web Hack List

Later archive addition

Unleashing the Walking Dead: Understanding Cross-App Remote Infections on Mobile WebViews

Cross-app URL invocation lets a remote web page navigate another Android app's WebView, so malicious web content spreads between apps and persists there. The authors name this XAWI and chain infected apps' separate privileges into remote phishing, faking a login UI inside the real app's own WebView, and privilege escalation; fuzzing found about 7.4 percent of top apps exposed.

Record

Researcher
Tongxin Li, Xueqiang Wang, Mingming Zha, Kai Chen, XiaoFeng Wang, Luyi Xing, Xiaolong Bai, Nan Zhang and Xinhui Han
Format
Whitepaper

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Tongxin Li, Xueqiang Wang, Mingming Zha, Kai Chen, XiaoFeng Wang, Luyi Xing, Xiaolong Bai, Nan Zhang and Xinhui Han, first published at the original source. Preserved copies are kept so the citation survives its host.