Web Hack List

Later archive addition

Iframes/Popups Are Dangerous in Mobile WebView: Studying and Mitigating Differential Context Vulnerabilities

The paper identifies differential context vulnerabilities created when browser iframe and popup assumptions are carried into Android WebView’s different UI, navigation, and API model. DCV-Hunter finds prevalent origin hiding, message-integrity, popup-order, and navigation flaws that enable bridge abuse or phishing, and the proposed WebView changes mitigate them with about 2 ms overhead.

Record

Researcher
GuangLiang Yang, Jeff Huang and Guofei Gu

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of GuangLiang Yang, Jeff Huang and Guofei Gu, first published at the original source. Preserved copies are kept so the citation survives its host.