USENIX Security2023Top-tier venue
Medusa Attack: Exploring Security Hazards of In-App QR Code Scanning
Xing Han, Yuheng Zhang, Xue Zhang, Zeyuan Chen, Mingzhe Wang, Yiwei Zhang, Siqi Ma, Yu Yu, Elisa Bertino, Juanru Li
Abstract
Smartphone users are eliminating traditional QR codes as many apps have integrated QR code scanning as a built-in functionality. With the support of embedded QR code scanning components, apps can read QR codes and immediately execute relevant activities, such as boarding a flight. Handling QR codes in such an automated manner is obviously user-friendly. However, this automation also creates an opportunity for attackers to exploit apps through malicious QR codes if the apps fail to properly check these codes. In this paper, we systematize and contextualize attacks on mobile apps that use built-in QR code readers. We label these as MEDUSA attacks, which allow attackers to remotely exploit the in-app QR code scanning of a mobile app. Through a MEDUSA attack, remote attackers can invoke a specific type of app functions -Remotely Accessible Handlers (RAHs), and perform tasks such as sending authentication tokens or making a payment. We conducted an empirical study on 800 very popular Android and iOS apps with billions of users in the two largest mobile ecosystems, the US and mainland China mobile markets, to investigate the prevalence and severity of MEDUSA attack related security vulnerabilities. Based on our proposed vulnerability detection technique, we thoroughly examined the target apps and discovered that a wide range of them are affected. Among the 377/800 apps with in-app QR code scanning functionality, we found 123 apps containing 2,872 custom RAHs that were vulnerable to the MEDUSA attack. By constructing proof-of-concept exploits to test the severity, we confirmed 46 apps with critical or high-severity vulnerabilities, which allows attackers to access sensitive local resources or remotely modify the user data. Listing 11 Sample JavaSrcript Code of DSBridge var dsBridge=require("dsbridge"); var str=dsBridge.call("nativeMethod","arg");
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b140357b-1375-486d-b66a-99dd89561e17Cited by top-tier papers5
- Misdirection of Trust: Demystifying the Abuse of Dedicated URL Shortening ServiceZhibo Zhang, Lei Zhang, Zhangyue Zhang, Geng Hong et al.NDSS 2025
- What You Decode Depends on Where You Stand: Distance-Based Optical QR CodePulkit Garg, Robin Verma, Somitra Sanadhya, Gaurav GuptaUSENIX Security 2026
- Shielding QR Codes: Unveiling the Real-World Illicit Promotion Behind Adversarial QR CodesLijie Wu, Xiaoping Zhang, Mingxuan Liu, Yue Qin et al.USENIX Security 2026
- When Authorization Loses Its Meaning: Breaking and Fixing Third-Party Online PaymentsYongkang Xiao, Jing Chen, Min Shi, Kun He et al.USENIX Security 2026
- Demystifying the (In)Security of QR Code-based Login in Real-world DeploymentsXin Zhang, Xiaohan Zhang, Bo Zhao, Yuhong Nan et al.USENIX Security 2025
Builds on7
- Automated Generation of Event-Oriented Exploits in Android Hybrid AppsGuangliang Yang, Jeff Huang, Guofei GuNDSS 2018 · 79 citations
- Unleashing the Walking Dead: Understanding Cross-App Remote Infections on Mobile WebViewsTongxin Li, Xueqiang Wang, Mingming Zha, Kai Chen et al.CCS 2017 · 47 citations
- Study and Mitigation of Origin Stripping Vulnerabilities in Hybrid-postMessage Enabled Mobile ApplicationsGuangliang Yang, Jeff Huang, Guofei Gu, Abner MendozaS&P 2018 · 27 citations
- Iframes/Popups Are Dangerous in Mobile WebView: Studying and Mitigating Differential Context VulnerabilitiesGuangliang Yang, Jeff Huang, Guofei GuUSENIX Security 2019 · 21 citations
- Understanding and Mitigating Remote Code Execution Vulnerabilities in Cross-platform EcosystemFeng Xiao, Zheng Yang, Joey Allen, Guangliang Yang et al.CCS 2022 · 14 citations
Related papers
- Development, Evaluation, and Implementation of SEQR - a Usable Secure QR Code ScannerMattia Mossano, Maxime Fabian Veit, Tobias Länge, Benjamin Maximilian Berens et al.CHI 2026 · 1 citation
- Scanned and Scammed: Insecurity by ObsQRity? Measuring User Susceptibility and Awareness of QR Code-Based AttacksMarvin Kowalewski, Leona Lassak, Markus Dürmuth, Theodor SchnitzlerUSENIX Security 2025
- Do You See How I Pose? Using Poses as an Implicit Authentication Factor for QR Code PaymentChuxiong Wu, Qiang ZengUSENIX Security 2024 · 2 citations
- All your app links are belong to us: understanding the threats of instant apps based attacksYutian Tang, Yulei Sui, Haoyu Wang, Xiapu Luo et al.FSE 2020 · 22 citations
- iOS, Your OS, Everybody's OS: Vetting and Analyzing Network Services of iOS ApplicationsZhushou Tang, Ke Tang, Minhui Xue, Yuan Tian et al.USENIX Security 2020
