USENIX Security2017Top-tier venue
Measuring the Insecurity of Mobile Deep Links of Android
Fang Liu, Chun Wang, Andres Pico, Danfeng Yao, Gang Wang
Abstract
Mobile deep links are URIs that point to specific locations within apps, which are instrumental to web-to-app communications. Existing "scheme URLs" are known to have hijacking vulnerabilities where one app can freely register another app's schemes to hijack the communication. Recently, Android introduced two new methods "App links" and "Intent URLs" which were designed with security features, to replace scheme URLs. While the new mechanisms are secure in theory, little is known about how effective they are in practice. In this paper, we conduct the first empirical measurement on various mobile deep links across apps and websites. Our analysis is based on the deep links extracted from two snapshots of 160,000+ top Android apps from Google Play (2014 and 2016), and 1 million webpages from Alexa top domains. We find that the new linking methods (particularly App links) not only failed to deliver the security benefits as designed, but significantly worsen the situation. First, App links apply link verification to prevent hijacking. However, only 194 apps (2.2% out of 8,878 apps with App links) can pass the verification due to incorrect (or no) implementations. Second, we identify a new vulnerability in App link's preference setting, which allows a malicious app to intercept arbitrary HTTPS URLs in the browser without raising any alerts. Third, we identify more hijacking cases on App links than existing scheme URLs among both apps and websites. Many of them are targeting popular sites such as online social networks. Finally, Intent URLs have little impact in mitigating hijacking risks due to a low adoption rate on the web.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5e4f961b-eccb-45c1-bab3-605500a0dc03Cited by top-tier papers7
- All your app links are belong to us: understanding the threats of instant apps based attacksYutian Tang, Yulei Sui, Haoyu Wang, Xiapu Luo et al.FSE 2020 · 22 citations
- Automatic Discovery of Emerging Browser Fingerprinting TechniquesJunhua Su, Alexandros KapravelosWWW 2023 · 17 citations
- Component Security Ten Years Later: An Empirical Study of Cross-Layer Threats in Real-World Mobile ApplicationsKeke Lian, Lei Zhang, Guangliang Yang, Shuo Mao et al.FSE 2024 · 5 citations
- ReACt: A Resource-centric Access Control System for Web-app Interactions on AndroidXin Zhang, Yifan ZhangWWW 2021 · 3 citations
- SoK: History Doesn't Repeat Itself, but Android Design-Level Vulnerabilities Rhyme in OpenHarmonyHongkai Chen, Yuqing Yang, Chao Wang, Arpit Nandi et al.USENIX Security 2026
Builds on1
Related papers
- Vulnerable Implicit Service: A RevisitLingguang Lei, Yi He, Kun Sun, Jiwu Jing et al.CCS 2017 · 5 citations
- DeepExploitor: LLM-Enhanced Automated Exploitation of DeepLink Attack in Hybrid AppsZhangyue Zhang, Lei Zhang, Zhibo Zhang, Yongheng Liu et al.ASE 2025
- Racing for TLS Certificate Validation: A Hijacker's Guide to the Android TLS GalaxySajjad Pourali, Xiufen Yu, Lianying Zhao, Mohammad Mannan et al.USENIX Security 2024 · 7 citations
- Towards HTTPS Everywhere on Android: We Are Not There YetAndrea Possemato, Yanick FratantonioUSENIX Security 2020
- Unleashing the Walking Dead: Understanding Cross-App Remote Infections on Mobile WebViewsTongxin Li, Xueqiang Wang, Mingming Zha, Kai Chen et al.CCS 2017 · 47 citations
